Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A critical command injection vulnerability (CVE-2026-16812) in on-premises Arista VeloCloud Orchestrator (VCO) is under active exploitation, allowing remote code execution and potential system compromise. Arista has released patches and provided indicators of compromise.
Intelligence analysis by Gemini 2.5 Flash

A maximum-severity security flaw in Arista's on-premises VeloCloud Orchestrator, tracked as CVE-2026-16812, is being actively exploited in the wild. This command injection vulnerability enables remote attackers to execute arbitrary code, potentially compromising the orchestrator and its managed data. The U.S. CISA has added this flaw to its Known Exploited Vulnerabilities catalog, man…
Imagine your school has a special computer that controls all the other computers and smartboards. A secret door on this main computer was accidentally left open, and some sneaky people found it. They can now use this secret door to tell the main computer to do whatever they want, like changing settings or looking at private files. The company that made the computer has now given everyone a special lock to fix the door, and important government groups are telling everyone to put the lock on right away to keep their computers safe.
Analysis
The Critical Flaw in VeloCloud Orchestrator
Arista Networks has disclosed a maximum-severity security flaw, CVE-2026-16812, affecting on-premises versions of its VeloCloud Orchestrator (VCO). This vulnerability, boasting a CVSS score of 10.0, is an operating system command injection issue that could allow for arbitrary code execution. According to Arista, the affected functionality was intended for internal use only and was not meant to be remotely accessible, yet attackers have found a way to exploit it.
Successful exploitation of this flaw could severely compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. This is particularly concerning given that VCOs are central to managing software-defined wide area networks (SD-WANs), making them high-value targets for malicious actors. Arista has confirmed that hosted and dedicated versions of VCO were addressed proactively, but on-premises deployments remain vulnerable without patching.
Active Exploitation and Broader Implications
Arista has acknowledged that CVE-2026-16812 was externally discovered and is already under active exploitation in the wild. While the company did not disclose the exact timing of the vulnerability's disclosure or the number of impacted customers, the active exploitation status elevates the urgency for all users. As indicators of compromise (IoCs), Arista shared three specific IP addresses associated with the attacks, urging customers to block them and review logs for any presence of these malicious sources.
Compromises to the VCO platform are particularly dangerous as they may grant attackers access to connected VeloCloud Edge devices. This could lead to a cascade of security incidents, including credential rotation, unauthorized changes to device configurations, and potential data exfiltration. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has underscored the severity by adding CVE-2026-16812 to its Known Exploited Vulnerabilities (KEV) catalog, mandating Federal Civilian Executive Branch (FCEB) agencies to apply the necessary patches by July 30, 2026.
Urgent Mitigation and Federal Directives
For organizations unable to immediately update to a fixed VCO release, Arista recommends several interim mitigation steps. These include restricting access to the VCO web interface to trusted administrative networks, actively monitoring the VCO for access attempts from known malicious IP addresses, and checking for any unexpected outbound network activity from the VCO host. Furthermore, reviewing recent administrator activity for unauthorized changes is crucial to detect potential compromises.
CISA's inclusion of this flaw in its KEV catalog highlights a broader trend of actively exploited vulnerabilities requiring immediate attention. The agency also added a medium-severity Fortinet FortiOS SSL-VPN flaw (CVE-2025-68686) to the KEV catalog, with a patching deadline of August 10, 2026. The ongoing exploitation of critical flaws like Arista's VCO vulnerability and others, such as the unpatched Alibaba Fastjson library issue (CVE-2026-16723), underscores the persistent and evolving threat landscape that organizations must navigate with proactive patching and robust security practices.
Key points
- A maximum-severity command injection flaw (CVE-2026-16812) in on-premises Arista VeloCloud Orchestrator (VCO) is under active exploitation.
- The vulnerability allows remote attackers to execute arbitrary code, potentially compromising the orchestrator and managed data.
- Arista has released patches for affected VCO versions and provided Indicators of Compromise (IoCs) including three malicious IP addresses.
- The U.S. CISA has added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by July 30, 2026.
- Interim mitigation steps include restricting web interface access, monitoring for malicious IPs, and reviewing administrator activity.
With Arista providing patches and CISA issuing a directive, organizations have a clear path to remediation. Prompt application of these updates and adherence to recommended security practices could significantly reduce the attack surface and prevent widespread exploitation, safeguarding critical network infrastructure.
If organizations fail to apply the necessary patches quickly, the active exploitation of this maximum-severity flaw could lead to widespread compromise of VeloCloud Orchestrator instances. This could result in significant data breaches, network outages, and further access to connected edge devices, causing extensive operational and security damage.



