Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

A Critical Vulnerability in Arista’s VeloCloud Orchestrator Platform Has Been Exploited in the Wild

In a stark reminder of the ongoing threat landscape, Arista Networks has released patches for a critical-severity vulnerability affecting its VeloCloud Orchestrator (VCO) centralized management platform. The security flaw, tracked as CVE-2026-16812, has already been exploited by attackers as a zero-day, putting sensitive data and infrastructure at risk.

The vulnerability is particularly concerning due to its ease of exploitation. According to Arista, the bug can be exploited remotely without requiring special configuration or authentication. In fact, VCO is exposed by default, leaving organizations vulnerable if they haven’t taken steps to secure their management platform. This means that even with robust network security measures in place, attackers may still be able to gain access to sensitive systems and data.

The impact of a successful exploit could be severe. Arista warns that compromised confidentiality, integrity, and availability are all possible outcomes, putting at risk not only the orchestrator itself but also the data managed by it. Organizations relying on VCO for network management and orchestration should take immediate action to apply the patches released by Arista.

Only specific versions of VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom) are affected, with patches available for VCO 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. However, the fact that this vulnerability has been exploited in the wild as a zero-day should serve as a warning to all organizations using VCO – whether affected by the bug or not.

In related news, the US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-16812 to its Known Exploited Vulnerabilities (KEV) catalog. This means that federal agencies are being urged to patch the vulnerability within three days, as mandated by BOD 26-04.

As we’ve seen with other recent vulnerabilities, exploitation can happen quickly and silently. It’s essential for organizations to stay vigilant and regularly review their security posture. By doing so, they can identify potential weaknesses and take proactive steps to prevent attacks.

If you’re using VeloCloud Orchestrator On-Prem, make sure to apply the latest patches as soon as possible. This will help prevent exploitation of CVE-2026-16812 and reduce the risk of data breaches or system compromise. Don’t forget to review your security logs for any unusual activity, and consider implementing additional monitoring and detection tools to stay ahead of potential threats.

In today’s fast-paced threat landscape, staying informed and proactive is crucial for protecting against emerging vulnerabilities like CVE-2026-16812.


Source: SecurityWeek — 2026-07-28