


Perceptive Security
SOC/SIEM Consultancy

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
Published:
28 juli 2026 om 04:43:53
Alert date:
28 juli 2026 om 06:00:32
Source:
thehackernews.com
Network Infrastructure, Zero-Day Vulnerabilities, Critical Infrastructure
A maximum-severity vulnerability tracked as CVE-2026-16812 with a CVSS score of 10.0 has been discovered in on-premises versions of Arista VeloCloud Orchestrator (VCO). The flaw is an operating system command injection vulnerability that can lead to arbitrary code execution. Active exploitation of this vulnerability has been confirmed in the wild. The issue specifically affects on-premises deployments of VeloCloud Orchestrator. Due to its critical severity score and active exploitation status, organizations running on-prem VCO instances are at significant risk.
Technical details
CVE-2026-16812 is a maximum-severity (CVSS 10.0) OS command injection vulnerability in on-premises versions of Arista VeloCloud Orchestrator (VCO). The flaw allows a remote attacker to access privileged internal functionality that was intended for internal use only and is not meant to be remotely accessible. Successful exploitation enables arbitrary code execution and can compromise the confidentiality, integrity, and availability of the orchestrator and its managed data. Exploitation may also allow attackers to pivot to VeloCloud Edge devices. The vulnerability was externally discovered and has been confirmed as actively exploited in the wild. CISA has added it to the KEV catalog with a federal patch deadline of July 30, 2026. Additionally, CVE-2025-68686 (CVSS 5.3) affects Fortinet FortiOS SSL-VPN, allowing a remote unauthenticated attacker to bypass a patch for a symbolic link persistency mechanism via crafted HTTP requests — though an attacker must first compromise the product via another vulnerability. CVE-2026-16723 (CVSS 9.0) is a critical unpatched RCE vulnerability in Alibaba's Fastjson library affecting versions 1.2.68 through 1.2.83, exploitable without user interaction or elevated privileges.
Mitigation steps:
1. Upgrade Arista VCO on-premises to fixed versions: 5.2.3.14+, 6.1.3.4+, 6.4.2.4+, or 7.0.0.1+. Federal agencies must patch by July 30, 2026. 2. Block the identified attacker IP addresses: 8.19.75.217, 206.72.242.124, 206.72.242.162. 3. Review VCO web access logs, backend application logs, system logs, database logs, and file-system timestamps for signs of compromise. 4. If immediate patching is not possible: restrict VCO web interface access to trusted administrative networks, monitor for access from known malicious IPs, check for unexpected outbound network activity, and review recent administrator activity for unexpected changes. 5. If compromise is suspected: perform credential rotation, review administrator activity, validate managed device state, and restore or replace affected orchestrator instances from trusted sources. 6. For Fortinet FortiOS SSL-VPN (CVE-2025-68686): apply the patch released in February 2025; federal agencies must patch by August 10, 2026. 7. For Alibaba Fastjson (CVE-2026-16723): enable SafeMode or switch to a non-impacted build immediately, as no patch is currently available for versions 1.2.68 through 1.2.83.
Affected products:
Arista VeloCloud Orchestrator (VCO) on-premises 5.2.x prior to 5.2.3.14
Arista VeloCloud Orchestrator (VCO) on-premises 6.1.x prior to 6.1.3.4
Arista VeloCloud Orchestrator (VCO) on-premises 6.4.x prior to 6.4.2.4
Arista VeloCloud Orchestrator (VCO) on-premises 7.0.x prior to 7.0.0.1
Fortinet FortiOS SSL-VPN (CVE-2025-68686
patched February 2025)
Alibaba Fastjson library versions 1.2.68 through 1.2.83 (CVE-2026-16723
unpatched)
Related links:
https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
https://fortiguard.fortinet.com/psirt/FG-IR-25-934
https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html
Related CVE's:
Related threat actors:
IOC's:
8.19.75.217, 206.72.242.124, 206.72.242.162
This article was created with the assistance of AI technology by Perceptive.
