← Back to blog

Critical Arista VeloCloud Flaw Actively Exploited

A zero-day command injection vulnerability in Arista's VeloCloud Orchestrator is being actively exploited. Organizations using on-premises versions should take immediate action.

TL;DR

  • CVE-2026-16812 is a critical OS command injection flaw in Arista VeloCloud Orchestrator (CVSS 10.0).
  • Attackers are actively exploiting this vulnerability in the wild for remote code execution.
  • Only on-premises installations of VCO are affected; cloud-hosted instances are not impacted.
  • Organizations should immediately apply vendor patches or isolate affected systems.
  • This vulnerability allows full system compromise without authentication.

Security researchers have identified active exploitation of a critical vulnerability in Arista Networks' VeloCloud Orchestrator (VCO). The flaw, designated CVE-2026-16812, carries the maximum CVSS severity score of 10.0 and allows attackers to execute arbitrary commands on affected systems.

The vulnerability specifically impacts on-premises deployments of VeloCloud Orchestrator, which organizations use to manage SD-WAN infrastructure. Attackers exploiting this flaw can gain complete control over vulnerable systems, potentially leading to network-wide compromise and lateral movement within enterprise environments.

Vulnerability Details

  • CVE-2026-16812 is an operating system command injection vulnerability in Arista VeloCloud Orchestrator
  • The flaw receives a CVSS score of 10.0 (critical) due to its potential for remote code execution
  • Only on-premises installations of VCO are vulnerable; cloud-hosted services remain unaffected
  • No authentication is required to exploit this vulnerability, making it particularly dangerous
  • Successful exploitation grants attackers full system access and control

Recommended Actions

  • Organizations using on-premises VeloCloud Orchestrator should immediately check their version and patch status
  • Apply the latest security updates from Arista Networks as soon as possible
  • Isolate vulnerable systems from network access until patches can be applied
  • Monitor network logs for suspicious activity that may indicate attempted or successful exploitation
  • Consider implementing network segmentation to limit potential lateral movement if systems are compromised

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Critical Arista VeloCloud Flaw Actively Exploited — Agent Breach Blog | Agent Breach