Vulnerabilities

CVE-2026-16812: Arista Patches Zero-Day in VeloCloud Orchestrator

July 29, 2026 00:22 · 12 min read
CVE-2026-16812: Arista Patches Zero-Day in VeloCloud Orchestrator

CVE-2026-16812: Arista Patches Zero-Day in VeloCloud Orchestrator

Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. The vulnerability, tracked as CVE-2026-16812, is an unauthenticated OS command injection flaw with severity scores of 10.0, the maximum score that can be given to flaws.

VeloCloud Orchestrator Vulnerability

VeloCloud Orchestrator, also known as VCO, is a centralized management platform used to configure, monitor, and manage VeloCloud SD-WAN deployments and associated edge devices. According to an Arista security advisory, the vulnerability allows remote attackers to access privileged functionality that was intended only for internal use and should not be remotely accessible.

Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator, Arista warned. The company says VCO is supposed to be exposed by default, with no configuration option that can prevent this exposure. Attackers only require network access to the VCO web interface, and no VCO tenant or operator credentials are needed to exploit the flaw.

Affected Versions and Patch

The following VeloCloud Orchestrator on-premises versions are affected: VCO 5.2.x releases before 5.2.3.14, VCO 6.1.x releases before 6.1.3.4, VCO 6.4.x releases before 6.4.2.4, and VCO 7.0.x releases before 7.0.0.1. VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected. VeloCloud Gateway and VeloCloud Edge products are also not vulnerable to the flaw.

The company says the flaw is fixed in VCO versions 5.2.3.14, 6.1.3.4, and 6.4.2.4 and later. The affected software list also indicates that VCO 7.0.0.1 and later releases are not vulnerable.

Indicators of Compromise

While patches are being deployed, administrators should restrict access to the VCO web interface to administrative networks, monitor for connections from known malicious IP addresses, and review recent administrator activity for unusual changes. Arista shared three IP addresses that were seen exploiting the vulnerability: 8.19.75.217, 206.72.242.124, and 206.72.242.162.

Administrators are advised to block these IP addresses and review their logs for previous connections. However, it is possible that devices could have been compromised from other IPs, so this list is not definitive. Organizations should review VCO logs for signs of exploitation, including unusual web requests, connections from known malicious IP addresses, and unexpected outbound HTTP or HTTPS traffic.

Recommendations

Potentially affected organizations should rotate credentials, review administrator activity, validate managed devices, and consider restoring or replacing compromised instances. As successful exploitation can compromise both the orchestrator host and the data it manages, installing the security update may not be enough for systems that have already been breached.

Arista warns that compromising a VeloCloud Orchestrator instance could also give attackers access to VeloCloud Edge devices as well. Test every layer before attackers do. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The U.S. Cybersecurity and Infrastructure Security Agency has also added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog, confirming that the flaw is being used in attacks. CISA has ordered U.S. federal civilian executive branch agencies to mitigate the vulnerability by Thursday, July 30, 2026, as required by Binding Operational Directive 22-01.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free