Bottom line: A critical, actively exploited vulnerability in Arista VeloCloud Orchestrator allows access to internal host functions and requires immediate installation of the available patches.
A critical security vulnerability in Arista’s VeloCloud Orchestrator is currently being actively attacked and allows access to internal functions of the affected host. Patches are available and should be applied immediately.
Arista has confirmed that a critical vulnerability in VeloCloud Orchestrator, the central management component of the vendor’s SD-WAN solution, is being actively exploited. The vulnerability allows access to internal functions of the host, potentially giving attackers extensive control over the Orchestrator instance. Certain versions of the software are affected, for which Arista has already made patches available.
For CISOs, the active exploitation is the decisive factor: this is not a theoretical vulnerability but an attack campaign already observed in the wild. VeloCloud Orchestrator plays a central role in SD-WAN environments, as it manages the configuration and control of all connected edge devices. A compromise of this component can therefore affect an entire organization’s network infrastructure, including site connections and traffic routing.
Organizations running Arista VeloCloud Orchestrator should immediately check whether their versions are affected and prioritize applying the patches provided by Arista. Since active exploitation is already occurring, it is also advisable to review system logs for signs of prior compromise and to restrict access to the Orchestrator’s management interface to trusted network segments.
Source: www.security-insider.de · Published August 5, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.