Back to Blog
Cybersecurity July 29, 2026 4 min read

Max-Severity Arista VeloCloud Flaw (CVE-2026-16812, CVSS 10.0) Is Being Exploited Right Now

An unauthenticated command injection bug in VeloCloud Orchestrator gives remote attackers full control of SD-WAN infrastructure. CISA's federal patch deadline is July 30.

Max-Severity Arista VeloCloud Flaw (CVE-2026-16812, CVSS 10.0) Is Being Exploited Right Now

CVE-2026-16812, an unauthenticated OS command injection flaw in Arista’s VeloCloud Orchestrator, is under active exploitation and carries the maximum possible CVSS score: 10.0. Arista confirmed the bug was discovered externally and disclosed on July 28 that attackers are already using it in the wild. If you run VCO on-premises, this needs to be your first patch today, not this week.

The flaw lets a remote, unauthenticated attacker reach privileged functionality on the orchestrator host that was meant to be internal-only, then execute arbitrary operating system commands. No credentials required — just network access to the VCO web interface. Since VeloCloud Orchestrator manages SD-WAN configuration and traffic policy across an organization’s branch network, a full compromise here doesn’t stay contained to one box: it hands an attacker the console for every site the orchestrator manages. Observed exploitation involves attackers scanning for publicly exposed orchestrator endpoints and delivering payloads via crafted HTTP POST or GET requests to establish persistence.

Affected versions: VCO 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1 — on-premises deployments only; Arista’s cloud-hosted VCO instances are not affected by this advisory.

Fix: upgrade to 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1 immediately. CVE-2026-16812 is now in CISA’s Known Exploited Vulnerabilities catalog, with a July 30 patch deadline for U.S. federal civilian agencies — everyone else should treat that as the real-world deadline too, given confirmed in-the-wild exploitation. If you can’t patch same-day, pull the VCO admin interface off the public internet and restrict access to a management VLAN or VPN while you schedule the update. Known indicators of compromise include inbound traffic from 8.19.75.217, 206.72.242.124, and 206.72.242.162 — check orchestrator access logs for hits from those addresses now.

Arista hasn’t disclosed who’s behind the exploitation or exactly when it started, only that it predates their own discovery. That’s the pattern with maximum-severity, pre-auth RCE bugs in network management software: by the time a vendor confirms active exploitation, the window for “patch before you’re a target” has usually already closed for anyone with an internet-facing instance.

Sources

CVE-2026-16812 Arista VeloCloud SD-WAN zero-day