Arista VeloCloud CVE-2026-16812 Exploited, CISA Orders Patch

Arista confirmed CVE-2026-16812, a CVSS 10.0 OS command injection in VeloCloud Orchestrator, is actively exploited. CISA ordered federal patches by July 30.
Table of Contents
    Add a header to begin generating the table of contents

    Arista Networks confirmed that CVE-2026-16812 — a CVSS 10.0 maximum-severity unauthenticated OS command injection vulnerability in its VeloCloud Orchestrator on-premises installations — is under active in-the-wild exploitation. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on July 27, 2026, and issued a three-day deadline requiring federal civilian agencies to apply patches by July 30.

    CVE-2026-16812’s OS Command Injection in Arista VeloCloud Orchestrator

    VeloCloud Orchestrator is the management and policy layer for Arista’s SD-WAN product, controlling policy distribution and network routing across enterprise branch sites, headquarters, data centers, and cloud environments. CVE-2026-16812 is an OS command injection vulnerability in a code path that was intended solely for internal use and should never have been reachable from external networks. An unauthenticated remote attacker can send crafted requests to the exposed code path and execute arbitrary OS commands on the orchestrator server, compromising confidentiality, integrity, and availability of the SD-WAN management plane.

    The vulnerability affects multiple VCO release branches: VCO 5.2.x before 5.2.3.14, VCO 6.1.x before 6.1.3.4, VCO 6.4.x before 6.4.2.4, and VCO 7.0.x before 7.0.0.1. Organizations running Arista-hosted or dedicated VCO environments were patched in advance of the public disclosure and are not exposed through the standard managed deployment model.

    Active Exploitation Confirmed and Three Attacking IP Addresses Identified

    Arista disclosed that CVE-2026-16812 was exploited before the patch was widely deployed, making this a confirmed zero-day at the time of active attack activity. Arista identified three specific IP addresses associated with attacks: 8.19.75.217, 206.72.242.124, and 206.72.242.162. No threat actor attribution was provided in Arista’s advisory.

    Arista’s immediate guidance for organizations that cannot patch immediately is to restrict access to the VCO web interface and monitor for inbound traffic from the three identified attacker IP addresses. Neither action fully closes the exposure — interface restriction reduces the attack surface while a patch is staged, and IP blocking addresses the identified attacker infrastructure without accounting for additional attack sources.

    CISA’s Three-Day July 30 Federal Patch Deadline for CVE-2026-16812

    CISA’s addition of CVE-2026-16812 to the Known Exploited Vulnerabilities catalog on July 27 triggered the mandatory remediation timeline for federal civilian executive branch agencies under Binding Operational Directive 22-01. The deadline set for CVE-2026-16812 is July 30 — three days after the catalog addition. This compressed window reflects the CVSS 10.0 maximum severity rating and the confirmed active exploitation status. While federal agencies are formally bound by the KEV remediation deadline, the catalog functions as a prioritization signal across all organizations running on-premises VeloCloud Orchestrator.

    What Compromising VeloCloud Orchestrator Gives Attackers

    SD-WAN orchestrators occupy a privileged position in enterprise network architecture. VeloCloud Orchestrator handles policy distribution and routing decisions for every site in the SD-WAN fabric — headquarters, branches, data centers, and cloud gateways. An attacker who compromises the orchestrator at the management plane level can modify routing policies, intercept traffic between sites, redirect connections, and introduce persistent access points across the entire network the SD-WAN serves.

    Unlike a compromise of a single branch device, successful exploitation of VeloCloud Orchestrator provides network-wide visibility and control. Depending on the VCO process privileges and the organization’s SD-WAN topology, post-exploitation access can include exfiltration of management credentials, manipulation of traffic policies across all connected sites, and the ability to route traffic through attacker-controlled paths.

    Organizations running on-premises VCO should apply the patched versions immediately. For those unable to reach the patched releases before the exposure window closes, restricting inbound access to the VCO web interface to trusted IP ranges and blocking the three identified attacker IPs represent partial compensating controls while patches are staged. Because Arista has confirmed active exploitation, unpatched internet-accessible VCO instances should be treated as potentially compromised and investigated accordingly, not simply queued for routine patch deployment.

    Related Posts