Critical

Arista, VeloCloud Orchestrator, CVE-2026-16812, CISA KEV, zero-day, command injection, SD-WAN

Arista VeloCloud CVE-2026-16812 Exploited (CVSS 10.0)

Arista VeloCloud CVE-2026-16812 (CVSS 10.0) is an exploited on-prem VCO command-injection zero-day in CISA KEV. Affected versions, fixes, and IoCs.

Arista VeloCloud CVE-2026-16812 (CVSS 10.0) Exploited as Zero-Day

CVE-2026-16812 is a CVSS 10.0 OS command-injection flaw in on-premises Arista VeloCloud Orchestrator (VCO) that is being exploited as a zero-day. CISA added it to the Known Exploited Vulnerabilities catalog on July 27, 2026. Affected on-prem releases are VCO 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. If you run VCO on-premises, this is a patch-now, assume-breach situation.

Arista disclosed CVE-2026-16812 as a maximum-severity vulnerability (CVSS 10.0, CWE-78 OS command injection) in on-premises VeloCloud Orchestrator, the management plane for VeloCloud SD-WAN. According to Arista's advisory, the flaw lets a remote attacker reach privileged internal functionality that "was intended to be for internal use only and is not intended to be remotely accessible," and run operating-system commands that can compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. Arista says it was externally discovered and already known to be actively exploited, and it published three IP-address indicators of compromise in its advisory. The hosted and dedicated (cloud) versions of VCO were fixed in advance, so the exposure is the on-prem estate.

How severe is CVE-2026-16812?

It is as severe as the scale goes, and its danger is amplified by where it sits. A CVSS 10.0 means unauthenticated, remote, high-impact across confidentiality, integrity, and availability, and here that lands on the control plane of an SD-WAN rather than a single endpoint. EPSS currently places it around the 56th percentile for exploitation likelihood, but that model lags reality on a flaw CISA has already confirmed is being exploited in the wild; the KEV listing, not the percentile, is the signal that matters.

Detail

Value

CVE

CVE-2026-16812

CVSS

10.0 Critical (CWE-78, OS command injection)

Product

Arista VeloCloud Orchestrator (on-prem)

Status

Zero-day, actively exploited

CISA KEV

Yes, added 2026-07-27

Which VeloCloud Orchestrator versions are affected and fixed?

Only the on-premises VCO builds below the fixed releases are affected; the cloud-hosted and dedicated services were remediated ahead of disclosure. Match your branch to the fixed version and update.

VCO branch

Affected

Fixed in

5.2.x

before 5.2.3.14

5.2.3.14

6.1.x

before 6.1.3.4

6.1.3.4

6.4.x

before 6.4.2.4

6.4.2.4

7.0.x

before 7.0.0.1

7.0.0.1

Why is a VeloCloud Orchestrator flaw so dangerous?

Because the orchestrator sits above the network. Compromising VCO gives an attacker a lever over SD-WAN topology and a natural path to pivot laterally across every site it manages, which is the "one box, whole network" leverage defenders worry about most. A management plane that is reachable from the internet turns a single command-injection bug into potential control over how an entire organization's sites and traffic are wired together.

What should you do now?

Apply Arista's fix for your branch immediately and take the orchestrator's management interface off the public internet until you have. Because this is a KEV-listed zero-day, assume exploitation predates your patch: review VCO for unexpected OS command execution, check for the three IP-address indicators Arista published, and hunt for lateral movement into the sites the orchestrator controls. Confirm that VCO is not reachable from untrusted networks, then keep verifying it stays that way.

Our read

A CVSS 10.0 on the control plane of your network is the worst kind of exposure, and it is exactly the sort of internet-reachable management asset that annual testing looks at once a year. In our analysis of the 2025 KEV catalog, 67% of the vulnerabilities that were actually exploited would have been missed by an organization relying on an annual penetration test, and a same-day KEV zero-day on an SD-WAN orchestrator is precisely that gap in action. The orchestrator is attack surface; knowing continuously whether yours is reachable, and proving it with evidence, is the only defense that keeps pace with an actively exploited flaw. Patch to the fixed build, pull the management plane off the internet, and verify exposure continuously rather than annually.

Reporting by The Hacker News; affected and fixed versions per Arista's advisory; exploitation status per the CISA KEV catalog; severity per NVD. Sources linked above.

Related: Cl0p exploits PTC Windchill CVE-2026-12569 · Progress Kemp LoadMaster CVE-2026-8037 in CISA KEV

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.