ThreatBrief AI

Attackers Exploit CVSS 10.0 Arista VeloCloud Orchestrator Command Injection Flaw

Attackers exploit a CVSS 10.0 OS command injection in Arista VeloCloud Orchestrator On-Prem. CISA added CVE-2026-16812 to KEV with a July 30 federal patch deadline.

+ +

Published

Jul 29, 2026

Duration

4 min read

Risk Level

Critical

Why it matters

Arista VeloCloud Orchestrator (VCO) is the central management plane for one of the most widely deployed SD-WAN platforms in enterprise and government networks. A maximum-severity OS command injection vulnerability now under active exploitation gives unauthenticated remote attackers full control over the orchestrator host and, by extension, every managed edge device. With CISA ordering federal agencies to patch by July 30, 2026, and attacker IPs already identified in the wild, every organization running a self-hosted VCO instance should treat this as an emergency remediation event.

What happened

On July 27, 2026, Arista Networks published Security Advisory 0144 disclosing CVE-2026-16812, a critical OS command injection vulnerability in the on-premises version of VeloCloud Orchestrator. The flaw received the maximum CVSS v3.1 score of 10.0 and affects VCO 5.2.x through 7.0.x before the specified patched builds. Hosted and dedicated VCO deployments were remediated by Arista prior to public disclosure.

The same day, CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation and setting a July 30, 2026 deadline for Federal Civilian Executive Branch (FCEB) agencies to apply mitigations. Arista acknowledged the vulnerability was externally discovered and known to be actively exploited.

According to Arista, attackers are exploiting the flaw to access privileged internal functionality that was intended to be accessible only from within the system. Successful exploitation compromises the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. The company shared three IP addresses linked to the attacks: 8.19.75.217, 206.72.242.124, and 206.72.242.162.

Technical details

CVE-2026-16812 is an OS command injection vulnerability (CWE-78) in the VCO web interface. An unauthenticated remote attacker can trigger arbitrary OS command execution by sending crafted HTTP requests to exposed endpoints that were designed for internal use only. The CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) reflects the network-reachable, low-complexity, no-authentication-required nature of the flaw and its broad impact across confidentiality, integrity, and availability.

The following on-prem VCO versions are affected:

  • VCO 5.2.x releases prior to 5.2.3.14
  • VCO 6.1.x releases prior to 6.1.3.4
  • VCO 6.4.x releases prior to 6.4.2.4
  • VCO 7.0.x releases prior to 7.0.0.1

Arista also warned that compromises to the VCO platform may allow attackers access to the VeloCloud Edge devices managed by the orchestrator, expanding the blast radius to the entire SD-WAN infrastructure.

The vulnerability arrives alongside CISA’s concurrent addition of a Fortinet FortiOS SSL-VPN information disclosure flaw (CVE-2025-68686, CVSS 5.3) to the KEV catalog. Separately, an unpatched remote code execution vulnerability in Alibaba’s Fastjson library (CVE-2026-16723, CVSS 9.0) is also being actively exploited.

Defender actions

  1. Patch immediately: Upgrade VCO on-prem to the fixed releases — 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1 — following Arista’s upgrade instructions.
  2. Block attacker IPs: Add 8.19.75.217, 206.72.242.124, and 206.72.242.162 to blocklists at the network perimeter and monitor for connections from these addresses.
  3. Restrict network access: If immediate patching is not possible, restrict access to the VCO web interface to trusted administrative networks only.
  4. Log review: Examine VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps for signs of compromise. Look for unexpected outbound connections, unknown administrator activity, and modified or dropped files.
  5. Credential rotation: Rotate all credentials accessible from the affected VCO instance, including edge device credentials, in case the orchestrator was already compromised.
  6. CISA KEV compliance: Federal agencies must apply fixes by July 30, 2026 per BOD 26-04.