Skip to content

Arista VeloCloud Orchestrator: Critical Vulnerability Actively Exploited

In brief: Arista is patching an already actively exploited critical vulnerability in VeloCloud Orchestrator that allows access to internal host functions – updates should be applied immediately.

A critical security vulnerability in Arista’s VeloCloud Orchestrator is already being actively attacked and allows access to internal functions of the host. Patches are available and should be applied immediately.

Arista Networks has confirmed a critical vulnerability in its VeloCloud Orchestrator that is currently being actively exploited. VeloCloud Orchestrator is the central management component in Arista SD-WAN environments and controls configuration, monitoring, and orchestration of connected edge devices. The vulnerability allows attackers to access internal functions of the underlying host. Arista has provided patches, and affected versions should be updated immediately.

Since the Orchestrator represents a central control instance for the entire SD-WAN infrastructure, a successful compromise can have far-reaching consequences: attackers who gain access to internal host functions can potentially manipulate configurations, view or redirect network traffic, and move laterally into connected network segments. For organizations with distributed sites relying on Arista SD-WAN, the Orchestrator’s central role makes it a particularly attractive attack target.

CISOs should check whether VeloCloud Orchestrator instances are in use within their own network or at managed service providers, and verify the patch status immediately. Since exploitation is already occurring actively, timely updating is more urgent than with purely theoretical vulnerabilities. Additionally, it is advisable to review access logs for unusual activity and restrict management access to the Orchestrator to necessary IP ranges.


Source: www.security-insider.de · Published August 5, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: