CVE-2026-86108
Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command execution with elevated privileges on the affected VeloCloud Edge.
- Published Sep 16, 2026
- CVSS 7.5 high
- 0.6% chance of exploitation in the next 30 days (EPSS)