Skip to content

Arista VeloCloud Orchestrator: CVE-2026-16812 Actively Exploited

The Bottom Line: Critical unauthenticated command injection in Arista VeloCloud Orchestrator On-Premises is actively exploited; CISA orders remediation by 30 July 2026.

A critical command injection vulnerability (CVE-2026-16812, CVSS 10.0) in on-premises installations of the Arista VeloCloud Orchestrator enables unauthenticated access to the host. CISA has added the vulnerability to the Catalog of Known Exploited Vulnerabilities (KEV) with a remediation deadline of 30 July 2026 for US federal agencies.

The vulnerability CVE-2026-16812 affects exclusively on-premises installations of the VeloCloud Orchestrator (VCO) and enables operating system command injection without prior authentication. Successful exploitation compromises the confidentiality, integrity and availability of the orchestrator and managed data. Hosted and dedicated instances have already been updated by the vendor.

Affected versions are VCO 5.2.x prior to 5.2.3.14, VCO 6.1.x prior to 6.1.3.4, VCO 6.4.x prior to 6.4.2.4 and VCO 7.0.x prior to 7.0.0.1. As indicators of compromise, Arista published the IP addresses 8.19.75.217, 206.72.242.124 and 206.72.242.162. If timely patching is not feasible, restricting administrative access to trusted networks is recommended.

For CISOs it is relevant that a compromise of the VCO host could potentially also provide access to managed VeloCloud Edge devices. This requires, following patch deployment, a review of all devices connected to the orchestrator for anomalies as well as a reassessment of network segmentation between the management platform and edge infrastructure.


Source: www.it-daily.net · Published 28 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: