Arista fixes actively exploited VeloCloud Orchestrator command-injection flaw
Arista has released patches for a critical vulnerability in on-premises VeloCloud Orchestrator (VCO) after confirming that attackers are exploiting the flaw in the wild.Tracked as CVE-2026-16812, the...
Arista has released patches for a critical vulnerability in on-premises VeloCloud Orchestrator (VCO) after confirming that attackers are exploiting the flaw in the wild.
Tracked as CVE-2026-16812, the issue is an unauthenticated operating-system command-injection vulnerability with a CVSS score of 10.0. VCO is used to centrally configure and manage VeloCloud SD-WAN environments and their edge devices. An attacker who can reach the platform’s web interface may invoke privileged functionality without needing tenant or administrator credentials.
Arista said exploitation could affect the confidentiality, integrity and availability of the orchestrator, along with information and systems managed through it. The vendor has not disclosed when the attacks began, how they are being conducted or who is responsible.
Affected and fixed releases
- VCO 5.2.x versions earlier than 5.2.3.14
- VCO 6.1.x versions earlier than 6.1.3.4
- VCO 6.4.x versions earlier than 6.4.2.4
- VCO 7.0.x versions earlier than 7.0.0.1
The vulnerability is resolved in versions 5.2.3.14, 6.1.3.4, 6.4.2.4 and subsequent releases. Arista said hosted and dedicated VCO services were updated before the advisory was issued. VeloCloud Gateway and VeloCloud Edge products are not affected directly, although compromise of an orchestrator could provide a path to managed Edge devices. Unsupported release branches have not been evaluated; customers using them should contact Arista for upgrade guidance.
The U.S. Cybersecurity and Infrastructure Security Agency has added the vulnerability to its Known Exploited Vulnerabilities catalog. Federal civilian agencies have been instructed to apply mitigations by July 30, 2026.
Recommended checks
During remediation, organizations should limit the VCO interface to trusted administrative networks and investigate logs for suspicious requests, unexpected outbound connections, configuration changes, command execution, file creation or access to databases and credentials. Arista identified these IP addresses as exploitation sources: 8.19.75.217, 206.72.242.124 and 206.72.242.162.
Because other infrastructure may also have been used, the indicators are not comprehensive. Suspected victims should preserve logs and file timestamps, rotate credentials, review administrator activity, validate managed devices and consider rebuilding compromised instances. Patching alone may not remove an attacker’s access if exploitation occurred before the update.
