Critical Arista VeloCloud Flaw Actively Exploited
A zero-day command injection vulnerability in Arista's VeloCloud Orchestrator is being actively exploited. Organizations using on-premises versions should take immediate action.
TL;DR
- CVE-2026-16812 is a critical OS command injection flaw in Arista VeloCloud Orchestrator (CVSS 10.0).
- Attackers are actively exploiting this vulnerability in the wild for remote code execution.
- Only on-premises installations of VCO are affected; cloud-hosted instances are not impacted.
- Organizations should immediately apply vendor patches or isolate affected systems.
- This vulnerability allows full system compromise without authentication.
Security researchers have identified active exploitation of a critical vulnerability in Arista Networks' VeloCloud Orchestrator (VCO). The flaw, designated CVE-2026-16812, carries the maximum CVSS severity score of 10.0 and allows attackers to execute arbitrary commands on affected systems.
The vulnerability specifically impacts on-premises deployments of VeloCloud Orchestrator, which organizations use to manage SD-WAN infrastructure. Attackers exploiting this flaw can gain complete control over vulnerable systems, potentially leading to network-wide compromise and lateral movement within enterprise environments.
Vulnerability Details
- CVE-2026-16812 is an operating system command injection vulnerability in Arista VeloCloud Orchestrator
- The flaw receives a CVSS score of 10.0 (critical) due to its potential for remote code execution
- Only on-premises installations of VCO are vulnerable; cloud-hosted services remain unaffected
- No authentication is required to exploit this vulnerability, making it particularly dangerous
- Successful exploitation grants attackers full system access and control
Recommended Actions
- Organizations using on-premises VeloCloud Orchestrator should immediately check their version and patch status
- Apply the latest security updates from Arista Networks as soon as possible
- Isolate vulnerable systems from network access until patches can be applied
- Monitor network logs for suspicious activity that may indicate attempted or successful exploitation
- Consider implementing network segmentation to limit potential lateral movement if systems are compromised
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.