Max-Severity Arista VeloCloud Flaw (CVE-2026-16812, CVSS 10.0) Is Being Exploited Right Now
An unauthenticated command injection bug in VeloCloud Orchestrator gives remote attackers full control of SD-WAN infrastructure. CISA's federal patch deadline is July 30.
CVE-2026-16812, an unauthenticated OS command injection flaw in Arista’s VeloCloud Orchestrator, is under active exploitation and carries the maximum possible CVSS score: 10.0. Arista confirmed the bug was discovered externally and disclosed on July 28 that attackers are already using it in the wild. If you run VCO on-premises, this needs to be your first patch today, not this week.
The flaw lets a remote, unauthenticated attacker reach privileged functionality on the orchestrator host that was meant to be internal-only, then execute arbitrary operating system commands. No credentials required — just network access to the VCO web interface. Since VeloCloud Orchestrator manages SD-WAN configuration and traffic policy across an organization’s branch network, a full compromise here doesn’t stay contained to one box: it hands an attacker the console for every site the orchestrator manages. Observed exploitation involves attackers scanning for publicly exposed orchestrator endpoints and delivering payloads via crafted HTTP POST or GET requests to establish persistence.
Affected versions: VCO 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1 — on-premises deployments only; Arista’s cloud-hosted VCO instances are not affected by this advisory.
Fix: upgrade to 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1 immediately. CVE-2026-16812 is now in CISA’s Known Exploited Vulnerabilities catalog, with a July 30 patch deadline for U.S. federal civilian agencies — everyone else should treat that as the real-world deadline too, given confirmed in-the-wild exploitation. If you can’t patch same-day, pull the VCO admin interface off the public internet and restrict access to a management VLAN or VPN while you schedule the update. Known indicators of compromise include inbound traffic from 8.19.75.217, 206.72.242.124, and 206.72.242.162 — check orchestrator access logs for hits from those addresses now.
Arista hasn’t disclosed who’s behind the exploitation or exactly when it started, only that it predates their own discovery. That’s the pattern with maximum-severity, pre-auth RCE bugs in network management software: by the time a vendor confirms active exploitation, the window for “patch before you’re a target” has usually already closed for anyone with an internet-facing instance.
Sources
Related reading
- Cybersecurity Cisco's 7th SD-WAN Zero-Day of 2026: CVE-2026-20245 Enables Root Execution — No Patch Available
- Cybersecurity Cisco Firewall Management Center Zero-Day (CVE-2026-20316) Exploited in the Wild — CISA Sets August 1 Deadline
- Cybersecurity Federal Agencies Have Until Tomorrow to Patch an Actively Exploited AD FS Zero-Day