<- ALL CYBER NEWS
Critical
Arista, VeloCloud Orchestrator, CVE-2026-16812, CISA KEV, zero-day, command injection, SD-WAN

Arista VeloCloud CVE-2026-16812 (CVSS 10) Exploited
CVE-2026-16812, a CVSS 10.0 OS command injection in on-prem Arista VeloCloud Orchestrator, is a zero-day now in CISA KEV. Patch the SD-WAN orchestrator now.
CVE-2026-16812 is a CVSS 10.0 OS command injection flaw in on-premises Arista VeloCloud Orchestrator (VCO) that is being exploited as a zero-day. CISA added it to the KEV catalog on 27 July. If you run VCO on-prem, this is a patch-now, assume-breach situation.
What happened. Arista disclosed CVE-2026-16812, a maximum-severity (CVSS 10.0, CWE-78 OS command injection) vulnerability in on-premises VeloCloud Orchestrator, the management plane for VeloCloud SD-WAN. A remote attacker can reach privileged internal functionality and run operating-system commands. It is under active exploitation, and CISA added it to its Known Exploited Vulnerabilities catalog the same day.
How severe is CVE-2026-16812?
Detail | Value |
|---|---|
CVE | CVE-2026-16812 |
CVSS | 10.0 Critical (CWE-78, OS command injection) |
Product | Arista VeloCloud Orchestrator (on-prem) |
Status | Zero-day, actively exploited |
CISA KEV | Yes - added 2026-07-27 |
Who is affected. Organisations running on-premises VeloCloud Orchestrator. The cloud-hosted service is not the focus here; the on-prem estate is. Because VCO orchestrates your SD-WAN, a compromise is not one box - it is the control plane for how sites and traffic are wired together.
Why is a VeloCloud Orchestrator flaw so dangerous?
Because the orchestrator sits above the network. Compromising VCO gives an attacker a lever over SD-WAN topology and a natural path to pivot laterally across the sites it manages - exactly the "one box, whole network" leverage defenders are worried about.
What should you do now?
Apply Arista's fix immediately and take the orchestrator's management interface off the public internet until you have. Because this is a KEV-listed zero-day, assume exploitation predates your patch: review VCO for unexpected OS command execution and hunt for lateral movement into the sites it controls.
Our read. A CVSS 10.0 on the control plane of your network is the worst kind of exposure, and it is exactly the sort of internet-reachable management asset that annual testing looks at once a year. In our analysis of the 2025 KEV catalog, 67% of vulnerabilities that were actually exploited would have been missed by an organisation relying on an annual penetration test. The orchestrator is attack surface; knowing continuously whether yours is reachable is the only defence that keeps pace with a same-day KEV zero-day.
Reporting by The Hacker News; exploitation status per the CISA KEV catalog; severity per NVD. Sources linked above.
Related: Cl0p exploits PTC Windchill CVE-2026-12569 and our KEV pentest analysis.