Published Monday, July 27, 2026 at 10:15 PM PT

BLUF: Arista has patched a maximum-severity (CVSS 10.0) unauthenticated command injection flaw in on-premises VeloCloud Orchestrator (VCO) that is actively exploited in the wild. Affected on-premises deployments require immediate patching; no credentials needed to trigger. CISA has ordered U.S. federal agencies to remediate by 30 July 2026. Hosted/Dedicated VCO instances are already patched.
DETAILS
- Vulnerability: CVE-2026-16812 — unauthenticated OS command injection in VeloCloud Orchestrator on-premises deployments; CVSS 10.0 (maximum).
- Attack vector: Remote, network-accessible. Exploits privileged functionality exposed on the VCO web interface; no tenant or operator credentials required.
- Active exploitation confirmed: CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog; Arista confirms active attacks in the wild but has not disclosed timing, threat actor identity, or exploitation techniques.
- Malicious IPs identified: Three IP addresses linked to exploitation attempts: 8.19.75.217, 206.72.242.124, 206.72.242.162.
- Scope: VeloCloud Orchestrator on-premises only. VCO Hosted and Dedicated deployments patched pre-disclosure. VeloCloud Gateway and Edge products are not vulnerable.
AFFECTED VERSIONS
| VCO Release | Vulnerable | Fixed |
|---|---|---|
| 5.2.x | Before 5.2.3.14 | 5.2.3.14+ |
| 6.1.x | Before 6.1.3.4 | 6.1.3.4+ |
| 6.4.x | Before 6.4.2.4 | 6.4.2.4+ |
| 7.0.x | Before 7.0.0.1 | 7.0.0.1+ |
End-of-support release trains have not been assessed; contact Arista TAC for upgrade guidance.
IMPACT
Successful exploitation compromises the confidentiality, integrity, and availability of the orchestrator and all data managed by it. VeloCloud Orchestrator is a centralized management platform for SD-WAN deployments and edge devices; compromise enables attackers to manipulate routing, intercept traffic, and maintain persistent access to downstream network infrastructure.
Organizations operating VCO on-premises deployments with internet-facing management interfaces are at immediate risk. VCO is designed to be network-accessible by default—no configuration option can prevent exposure—making all unpatched instances vulnerable.
RECOMMENDED ACTIONS — IMMEDIATE
Identify on-premises VCO deployments and confirm current version (run
show versionor check VCO UI).Prioritize patching to one of the fixed versions listed above.
Restrict network access to VCO web interface to administrative/trusted networks pending patches.
Block malicious IPs (8.19.75.217, 206.72.242.124, 206.72.242.162) at perimeter.
Review VCO audit logs for indicators of compromise:
- Unusual web requests with encoded characters, URL-like path components, or references to internal services
- Connections from the three malicious IPs above
- Unexpected outbound HTTP/HTTPS from VCO host
- Unauthorized configuration changes, privileged maintenance activity, or command execution
For U.S. federal agencies: CISA Binding Operational Directive 22-01 mandates mitigation by 30 July 2026.
SOURCES
BleepingComputer, 27 July 2026 — “Arista patches VeloCloud Orchestrator zero-day exploited in attacks”
Arista Networks Security Advisory — CVE-2026-16812
CISA Known Exploited Vulnerabilities Catalog (27 July 2026)
Recent high-severity events at publish time:

