Arista VeloCloud Orchestrator Command Injection Flaw Under Active Exploitation

Answer Brief

Attackers are actively exploiting CVE-2026-16812, a critical command injection vulnerability in on-premises Arista VeloCloud Orchestrator (VCO) versions, enabling arbitrary code execution and potential compromise of managed SD-WAN infrastructure. CISA has added the flaw to its KEV catalog with a July 30, 2026 patch deadline for federal agencies.

Signal Timeline

A quick visual path for analysts before reading the full brief.

Timeline
  1. 1

    Arista publishes advisory on active exploitation of CVE-2026-16812 in VeloCloud Orchestrator on-prem versions

  2. 2

    CISA adds CVE-2026-16812 to Known Exploited Vulnerabilities (KEV) catalog

  3. 3

    Deadline for FCEB agencies to patch CVE-2026-16812 per CISA KEV requirement

  4. 4

    Extended deadline for federal agencies to apply patches (per source context)

Executive Summary: Attackers are actively exploiting CVE-2026-16812, a critical command injection vulnerability in on-premises Arista VeloCloud Orchestrator (VCO) versions, enabling arbitrary code execution and potential compromise of managed SD-WAN infrastructure. CISA has added the flaw to its KEV catalog with a July 30, 2026 patch deadline for federal agencies.

Why It Matters

The active exploitation of CVE-2026-16812 in Arista VeloCloud Orchestrator (VCO) represents a significant threat to enterprise and government networks relying on SD-WAN infrastructure for secure, optimized connectivity. As a command injection flaw with a CVSS score of 10.0, it allows unauthenticated remote attackers to execute arbitrary code on the VCO host by exploiting functionality intended for internal use only. This level of access could lead to full compromise of the orchestrator, enabling attackers to manipulate or disrupt SD-WAN edge devices, intercept or alter traffic, and potentially pivot into connected enterprise or cloud environments. The vulnerability affects multiple recent versions of VCO across the 5.2.x, 6.1.x, 6.4.x, and 7.0.x release lines, indicating a widespread exposure window that spans several years of deployments. Arista’s advisory confirms that hosted and dedicated versions were patched in advance, leaving only on-premises customers at risk—a distinction that highlights the importance of deployment model in vulnerability exposure. CISA’s rapid inclusion of CVE-2026-16812 in the Known Exploited Vulnerabilities (KEV) catalog underscores the severity and immediacy of the threat. By mandating patching for FCEB agencies by July 30, 2026 (with an extended timeline to August 10, 2026 noted in the source), CISA signals that active exploitation is not only occurring but poses a credible risk to critical infrastructure and government operations. The KEV catalog prioritizes vulnerabilities under active attack, and this addition reflects real-world weaponization of the flaw. Organizations outside the federal sector should treat this as a high-priority signal to review their VCO deployments, apply patches immediately, and implement compensating controls such as restricting web interface access to trusted networks and monitoring for IoCs. The indicators of compromise shared by Arista—three specific IP addresses (8.19.75.217, 206.72.242.124, 206.72.242.162)—provide actionable intelligence for network defenders. Blocking these IPs at firewalls and reviewing VCO logs for connections from these sources is a critical first step in intrusion detection. Arista also recommends preserving logs (web access, backend, system, database, and file-system timestamps) before remediation if operationally feasible, which supports forensic analysis and incident response. Additional monitoring guidance includes checking for unexpected outbound network activity from the VCO host and reviewing administrator logs for unauthorized changes, helping detect post-exploitation behavior such as credential manipulation or lateral movement. A notable risk highlighted by Arista is that compromise of the VCO platform may extend to managed VeloCloud Edge devices. Since the orchestrator manages configuration, policy, and firmware for these edge nodes, attackers could potentially use privileged access to rotate credentials, alter device states, or disrupt SD-WAN connectivity across distributed sites. This amplifies the impact beyond the orchestrator itself to the broader network infrastructure it controls, affecting branch offices, retail locations, manufacturing sites, and remote workers relying on VeloCloud for WAN optimization and security. The timing of this exploit coincides with other KEV additions, including CVE-2025-68686 in Fortinet FortiOS SSL-VPN (CVSS 5.3), which was patched earlier in February 2026, and CVE-2026-16723 in Alibaba’s Fastjson library (CVSS 9.0), which remains unpatched. While the Fortinet flaw requires prior system-level compromise to exploit, the Fastjson vulnerability allows remote code execution without user interaction or elevated privileges—similar in impact to the VCO flaw. The presence of multiple high-severity, actively exploited vulnerabilities in widely used enterprise software underscores a heightened threat environment where attackers are chaining or prioritizing exploits in critical infrastructure components. For security, cloud, and operations teams, this event reinforces the need for rigorous asset inventory, version tracking, and rapid patch management for on-premises network orchestration platforms. Organizations should verify their VCO version against the affected ranges, apply the latest patched releases immediately, and implement network segmentation to limit exposure of management interfaces. Where patching is delayed, restricting access to trusted administrative networks and enhancing monitoring for anomalous behavior are essential interim measures. The exploitation of VCO also highlights the risk inherent in centralized network management platforms: while they improve operational efficiency, they create high-value targets whose compromise can have cascading effects across the entire managed infrastructure.

Event Type: security
Importance: high

Affected Companies

  • Alibaba
  • Arista
  • CISA
  • Fortinet

Affected Sectors

  • SD-WAN
  • cloud infrastructure
  • enterprise IT
  • government IT
  • network security

Key Numbers

  • CVSS score for CVE-2026-16812: 10.0
  • CVSS score for CVE-2025-68686: 5.3
  • CVSS score for CVE-2026-16723: 9.0

Timeline

  1. Arista publishes advisory on active exploitation of CVE-2026-16812 in VeloCloud Orchestrator on-prem versions
  2. CISA adds CVE-2026-16812 to Known Exploited Vulnerabilities (KEV) catalog
  3. Deadline for FCEB agencies to patch CVE-2026-16812 per CISA KEV requirement
  4. Extended deadline for federal agencies to apply patches (per source context)
  5. Fortinet patches CVE-2025-68686 in FortiOS SSL-VPN

Frequently Asked Questions

What is CVE-2026-16812 and why is it critical?

CVE-2026-16812 is a maximum-severity (CVSS 10.0) operating system command injection flaw in on-premises Arista VeloCloud Orchestrator (VCO) that allows remote attackers to execute arbitrary code, potentially compromising the orchestrator and managed SD-WAN edge devices. It is actively exploited in the wild.

Which versions of Arista VeloCloud Orchestrator are affected by CVE-2026-16812?

Affected versions include VCO 5.2.x prior to 5.2.3.14, VCO 6.1.x prior to 6.1.3.4, VCO 6.4.x prior to 6.4.2.4, and VCO 7.0.x prior to 7.0.0.1. Hosted and dedicated versions were patched in advance.

What actions has CISA taken regarding CVE-2026-16812?

CISA has added CVE-2026-16812 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patch by July 30, 2026, with an extended deadline of August 10, 2026 mentioned in the source.

What indicators of compromise (IoCs) did Arista share for CVE-2026-16812 exploitation?

Arista shared three IP addresses associated with active attacks: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Organizations are advised to block these IPs and review logs for signs of compromise.

Are there other vulnerabilities mentioned in the source that are under active exploitation?

Yes, the source notes CVE-2025-68686 (CVSS 5.3) in Fortinet FortiOS SSL-VPN and CVE-2026-16723 (CVSS 9.0) in Alibaba's Fastjson library were also added to or noted in the KEV catalog due to active exploitation, though Fortinet's flaw was patched in February 2026.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *