Arista patches VeloCloud Orchestrator zero-day exploited in attacks

A critical vulnerability in Arista’s VeloCloud Orchestrator (VCO) platform has been exploited by attackers, prompting the company to issue an emergency patch. The flaw, tracked as CVE-2026-16812, is a maximum-severity command injection bug that allows unauthenticated attackers to access privileged functionality and potentially compromise the confidentiality, integrity, and availability of the orchestrator and its managed data.

VCO is a centralized management platform used to configure, monitor, and manage VeloCloud SD-WAN deployments and associated edge devices. The vulnerability affects on-premises VCO versions 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, and 6.4.x before 6.4.2.4. Arista has released patches for these versions, which can be downloaded from their website.

The good news is that VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected by this vulnerability. Similarly, VeloCloud Gateway and VeloCloud Edge products are also not vulnerable to the flaw.

However, the bad news is that attackers only require network access to the VCO web interface to exploit the flaw, and no VCO tenant or operator credentials are needed. This makes it a particularly attractive target for threat actors looking to compromise sensitive data and disrupt business operations.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog, confirming that the flaw is being used in attacks. CISA has ordered US federal civilian executive branch agencies to mitigate the vulnerability by Thursday, July 30, 2026.

To protect themselves from this threat, administrators should restrict access to the VCO web interface to administrative networks, monitor for connections from known malicious IP addresses, and review recent administrator activity for unusual changes. Arista has shared three IP addresses that were seen exploiting the vulnerability: 8.19.75.217, 206.72.242.124, and 206.72.242.162.

Organizations should also review VCO logs for signs of exploitation, including unusual web requests, connections from known malicious IP addresses, unexpected outbound HTTP or HTTPS traffic, unauthorized configuration changes, and suspicious access to VCO databases.

If compromise is suspected, organizations should preserve all logs and filesystem timestamps before remediation. They should also rotate credentials, review administrator activity, validate managed devices, and consider restoring or replacing compromised instances.

In short, this vulnerability highlights the importance of keeping software up-to-date and monitoring system activity for signs of exploitation. Organizations that have not yet patched their VCO installations should do so immediately to prevent potential attacks.


Source: Bleeping Computer — 2026-07-27