Arista has released patches for a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments that attackers are already exploiting in the wild. The flaw, tracked as CVE-2026-16812, carries a CVSS score of 10.0.
VCO is a centralized management platform used to configure, monitor, and manage VeloCloud SD-WAN deployments and their associated edge devices. According to Arista’s security advisory, the vulnerability allows unauthenticated remote attackers to reach privileged functionality that was intended for internal use only and should never have been remotely accessible. No VCO tenant or operator credentials are required, and only network access to the VCO web interface is needed to exploit the flaw.
Arista says on-premises VCO is exposed by default with no configuration option to prevent that exposure, a design detail that significantly widens the attack surface for organizations running affected versions. Successful exploitation can compromise the confidentiality, integrity, and availability of the orchestrator itself and the data it manages, including device inventories, credentials, certificates, and cryptographic keys.
Affected Versions
The following on-premises VCO releases are vulnerable:
- VCO 5.2.x before 5.2.3.14
- VCO 6.1.x before 6.1.3.4
- VCO 6.4.x before 6.4.2.4
- VCO 7.0.x before 7.0.0.1
Fixes are available in VCO 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1 and later. VeloCloud Orchestrator Hosted and Dedicated deployments were patched prior to the advisory’s publication and are not affected, nor are VeloCloud Gateway and Edge products. Arista notes that end-of-support release trains have not been assessed for vulnerability, and customers on unsupported versions should contact Arista’s Technical Assistance Center for upgrade guidance.
Active Exploitation and Indicators
Arista says the vulnerability was discovered externally and confirms active exploitation, though it has not disclosed when attacks began, who is responsible, or the specific exploitation technique used. The company shared three IP addresses observed exploiting the flaw: 8.19.75.217, 206.72.242.124, and 206.72.242.162. This list is not considered exhaustive.
Administrators are urged to restrict VCO web interface access to administrative networks, monitor for connections from known malicious IPs, and review logs for unusual web requests, unexpected outbound traffic, unauthorized configuration changes, unexpected command execution, and suspicious access to credentials or device inventories. Organizations suspecting compromise should preserve logs and filesystem timestamps before remediation, rotate credentials, validate managed devices, and consider restoring or replacing compromised orchestrator instances, since patching alone may not remediate an already-breached system.
CISA has added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and, under Binding Operational Directive 22-01, has ordered federal civilian executive branch agencies to remediate the flaw by July 30, 2026.
