Critical Arista VeloCloud Orchestrator zero-day
Arista released patches for a critical OS injection bug (CVE-2026-16812) in VeloCloud Orchestrator On-Prem after it was exploited in the wild; it can be triggered remotely without credentials.
Arista Networks on Monday released patches for a critical OS injection vulnerability in VeloCloud Orchestrator On-Prem, tracked as CVE-2026-16812. The flaw carries a CVSS score of 10 and was observed being exploited in the wild. It can be triggered remotely without tenant or operator credentials and requires only network access to the VCO web interface.
The vendor fixed the defect in VCO versions 5.2.3.14, 6.1.3.4, 6.4.2.4 and 7.0.0.1. Only the on-premises distribution is affected. Arista’s advisory confirms the issue was discovered externally and that exploitation is active. The advisory notes: “VCO is exposed by default. There is no configuration that can prevent the exposure.”
The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and directed federal agencies to remediate the issue within three days under Binding Operational Directive 26-04.
Arista provided monitoring and response guidance for operators. It recommends examining VCO web access logs for unexpected requests and unusual URL-like path components, and reviewing backend application, system and database logs for follow-up activity such as requests from suspicious IP addresses, outbound HTTP/S connections, and privileged actions that fall outside normal administrative workflows.
The vendor advised hunting for indicators including command execution, database exports, file creation, and unauthorized access to device inventories, configurations, certificates, credentials and key material. If compromise is suspected, operators should preserve relevant logs and file-system timestamps before remediation where operationally feasible.
Customers running on-prem orchestrators were urged to install the patched releases immediately. Because VCO instances are reachable by default, organizations were also advised to consider restricting network access to management interfaces while applying fixes. VeloCloud Orchestrator, originally distributed under Broadcom, is used to centrally manage SD-WAN deployments and device configurations.








