top of page
perceptive_background_267k.jpg

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

Published:

28 July 2026 at 00:49:44

Alert date:

28 July 2026 at 01:00:34

Source:

bleepingcomputer.com

Click to open the original link from this advisory

Network Infrastructure, Zero-Day Vulnerabilities, Critical Infrastructure

Arista has released patches for a maximum-severity command injection vulnerability affecting on-premises VeloCloud Orchestrator deployments. The vulnerability is being actively exploited in real-world attacks, making it a critical priority for affected organizations. VeloCloud Orchestrator is a network management platform used for SD-WAN deployments in enterprise environments. The zero-day nature of the exploitation means attackers were leveraging the flaw before a patch was available. Organizations running on-premises VeloCloud Orchestrator instances are urged to apply the patches immediately to prevent compromise.

Technical details

CVE-2026-16812 is a maximum-severity (CVSS 10.0) unauthenticated OS command injection vulnerability in Arista VeloCloud Orchestrator (VCO) on-premises deployments. The flaw allows remote attackers to access privileged functionality intended only for internal use. No authentication or credentials are required — only network access to the VCO web interface. Successful exploitation can compromise the confidentiality, integrity, and availability of the orchestrator and all data it manages, including potential lateral access to VeloCloud Edge devices. VCO is exposed by default with no configuration option to prevent this exposure. The vulnerability was discovered externally and is actively exploited in the wild. CISA has added it to the Known Exploited Vulnerabilities catalog.

Mitigation steps:

1. Apply patches immediately: upgrade to VCO versions 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1 or later. 2. Restrict access to the VCO web interface to administrative networks only. 3. Block known malicious IPs: 8.19.75.217, 206.72.242.124, 206.72.242.162. 4. Monitor VCO logs for: unusual web requests with encoded characters or abnormal request rates, unexpected outbound HTTP/HTTPS traffic, unauthorized configuration changes or privileged maintenance activity, unexpected command execution or file creation, suspicious access to VCO databases, credentials, certificates, or cryptographic keys. 5. Rotate credentials for all VCO-managed accounts. 6. Review administrator activity and validate managed devices. 7. If compromise is suspected, preserve logs and filesystem timestamps before remediation. 8. Consider restoring or replacing potentially compromised instances, as patching alone may not be sufficient for already-breached systems. 9. Organizations running end-of-support VCO versions should contact Arista TAC for upgrade options. 10. CISA-mandated deadline for U.S. federal civilian executive branch agencies: July 30, 2026.

Affected products:

Arista VeloCloud Orchestrator (VCO) on-premises 5.2.x before 5.2.3.14
Arista VeloCloud Orchestrator (VCO) on-premises 6.1.x before 6.1.3.4
Arista VeloCloud Orchestrator (VCO) on-premises 6.4.x before 6.4.2.4
Arista VeloCloud Orchestrator (VCO) on-premises 7.0.x before 7.0.0.1

Related links:

Related CVE's:

Related threat actors:

IOC's:

8.19.75.217, 206.72.242.124, 206.72.242.162

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page