VYPR
patchPublished Jul 27, 2026· 1 source

Arista Patches Critical VeloCloud Orchestrator Zero-Day Exploited in Attacks

Arista has released a patch for a critical command injection vulnerability (CVE-2026-16812) in on-premises VeloCloud Orchestrator deployments that is being actively exploited in the wild.

Arista has released a patch for a critical command injection vulnerability affecting on-premises VeloCloud Orchestrator (VCO) deployments, a flaw that has been actively exploited by attackers.

The vulnerability, tracked as CVE-2026-16812, is an unauthenticated OS command injection flaw that has been assigned the maximum severity score of 10.0. VCO is a centralized management platform used for configuring, monitoring, and managing VeloCloud SD-WAN deployments and associated edge devices.

According to an Arista security advisory, the vulnerability allows remote attackers to access privileged functionality that was intended for internal use only and should not be remotely accessible. Successful exploitation could compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. Arista noted that VCO is typically exposed by default, and attackers only require network access to the web interface, without needing any tenant or operator credentials.

The flaw was discovered externally, and Arista has confirmed it is being actively exploited, though details regarding the timeline, threat actors, or specific exploitation methods remain undisclosed. Affected on-premises versions include VCO 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. VeloCloud Orchestrator Hosted and Dedicated deployments have already been patched and are not affected, nor are VeloCloud Gateway and VeloCloud Edge products.

Arista has fixed the vulnerability in VCO versions 5.2.3.14, 6.1.3.4, and 6.4.2.4 and later. Releases of VCO 7.0.0.1 and later are also not vulnerable. The company advises customers running end-of-support versions to contact their technical assistance center for upgrade options.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-16812 to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal civilian executive branch agencies to implement mitigations by July 30, 2026, as per Binding Operational Directive 22-01.

In addition to patching, Arista recommends restricting access to the VCO web interface to administrative networks and monitoring for suspicious activity. The company shared three IP addresses observed exploiting the vulnerability (8.19.75.217, 206.72.242.124, and 206.72.242.162) and advises blocking them while reviewing logs for connections from these or other potentially malicious sources. Indicators of compromise include unusual web requests, unexpected outbound traffic, unauthorized configuration changes, and suspicious access to VCO data.

Arista warns that compromise of a VeloCloud Orchestrator instance could grant attackers access to managed data and potentially to VeloCloud Edge devices as well. Organizations that suspect a breach should preserve logs, rotate credentials, review administrator activity, and consider restoring or replacing compromised instances.

Synthesized by Vypr AI