Arista VeloCloud Orchestrator Zero-Day CVE-2026-16812 Under Active Attack

A maximum-severity command-injection flaw in on-prem Arista VeloCloud Orchestrator is being exploited to fully compromise SD-WAN infrastructure, with CISA setting a July 30 patch deadline for federal agencies.

Arista VeloCloud Orchestrator Zero-Day CVE-2026-16812 Under Active Attack

A maximum-severity command-injection vulnerability in on-premises Arista VeloCloud Orchestrator (VCO) is being actively exploited in the wild, giving remote, unauthenticated attackers a route to arbitrary code execution on orchestrator hosts and, potentially, every VeloCloud Edge device beneath them.

CVSS 10.0, four release branches affected

Tracked as CVE-2026-16812, the flaw carries a CVSS score of 10.0 and affects VCO on-prem branches 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.2.4, and 7.0.x prior to 7.0.0.1. Arista's hosted and dedicated deployments were patched in advance and are not affected. The bug exposed privileged internal functionality that was never meant to be reachable over the network.

CISA KEV: patch by July 30

The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog on July 27, giving federal civilian agencies until July 30, 2026 to patch. Arista has published three attacker IP addresses as indicators of compromise (8.19.75.217, 206.72.242.124, 206.72.242.162) and is urging operators to preserve VCO web-access logs, backend and database logs, and file-system timestamps before remediating.

Command-injection exploitation of network orchestrator

Rotate credentials, isolate the orchestrator

Because a compromised orchestrator may extend to the VeloCloud Edge fleet, Arista is recommending credential rotation, review of administrator activity, validation of managed device state, and, where necessary, restoration or replacement of affected orchestrator instances from trusted sources. Where updating cannot happen immediately, teams should restrict web-interface access to trusted administrative networks and monitor for outbound traffic to the published IoCs.

The disclosure follows a busy stretch of KEV additions covered by us, including the Arista EOS tunnel-decap flaw CVE-2026-7473, the ongoing SonicWall SMA 1000 zero-days, and the Ruby on Rails Active Storage RCE CVE-2026-66066.

Reporting based on coverage from The Hacker News, BleepingComputer, SecurityWeek and Arista's own advisory 0144.

Category: Cyber Security

Tags: Cybersecurity Zero-Day CVE

Related Articles