Arista patches VeloCloud Orchestrator zero-day exploited in attacks

A critical vulnerability in Arista’s VeloCloud Orchestrator has been actively exploited by attackers, leaving organizations with potentially compromised networks and sensitive data at risk. The flaw, designated as CVE-2026-16812, is a maximum-severity command injection vulnerability that allows remote attackers to access privileged functionality without authentication.

VeloCloud Orchestrator (VCO) is a centralized management platform used for configuring, monitoring, and managing VeloCloud SD-WAN deployments. In its default configuration, VCO’s web interface is exposed to the internet, making it vulnerable to attacks from external networks. According to Arista, no configuration option exists to prevent this exposure, leaving organizations with limited control over who can access their VCO instances.

The vulnerability allows attackers to inject operating system commands, potentially compromising the confidentiality, integrity, and availability of both the orchestrator and managed data. The company has confirmed that CVE-2026-16812 is being actively exploited in attacks, but it has not disclosed details about the attackers’ identities or when the exploitation began. Arista has patched the vulnerability in VCO versions 5.2.3.14, 6.1.3.4, and 6.4.2.4 and later.

The affected software list includes VCO 5.2.x releases before 5.2.3.14, VCO 6.1.x releases before 6.1.3.4, and VCO 6.4.x releases before 6.4.2.4. However, VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published, making them immune to this vulnerability. Additionally, VeloCloud Gateway and VeloCloud Edge products are not vulnerable.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog, confirming that it is being used in attacks. CISA has ordered U.S. federal civilian executive branch agencies to mitigate the vulnerability by Thursday, July 30, 2026.

While patches are being deployed, administrators should take immediate action to protect their networks. This includes restricting access to the VCO web interface to administrative networks, monitoring for connections from known malicious IP addresses, and reviewing recent administrator activity for unusual changes. Arista has shared three IP addresses that were seen exploiting the vulnerability: 8.19.75.217, 206.72.242.124, and 206.72.242.162.

Administrators are advised to block these IP addresses and review their logs for previous connections. However, it is possible that devices could have been compromised from other IPs, so this list is not definitive. Organizations should also review VCO logs for signs of exploitation, including unusual web requests containing encoded characters or abnormally high request rates.

If compromise is suspected, organizations should preserve all logs and filesystem timestamps before remediation. Potentially affected organizations should rotate credentials, review administrator activity, validate managed devices, and consider restoring or replacing compromised instances. Installing the security update may not be enough for systems that have already been breached, as successful exploitation can compromise both the orchestrator host and the data it manages.

In conclusion, the CVE-2026-16812 vulnerability highlights the importance of regular software updates and security patching. Administrators should prioritize installing the latest patches to prevent potential attacks and ensure the integrity of their networks.


Source: Bleeping Computer — 2026-07-27