Mastodon Mastodon Mastodon Mastodon

Arista VeloCloud Orchestrator CVE-2026-16812 Under Active Exploitation

Photo of author

CyberSecureFox Editorial Team

Published:

The critical vulnerability CVE-2026-16812 with a maximum CVSS score of 10.0 in on-premises versions of Arista VeloCloud Orchestrator (VCO) has been confirmed as being actively exploited. The vulnerability allows a remote attacker to execute arbitrary operating system commands on the orchestrator host, which leads to complete compromise of the confidentiality, integrity, and availability of the SD-WAN management platform and all peripheral devices connected to it. CISA has added the vulnerability to the KEV catalog, setting a remediation deadline for federal agencies of July 30, 2026. Organizations using VCO on-premises must immediately update the system or apply access-limitation measures.

Technical details of the vulnerability

According to the Arista security advisory, CVE-2026-16812 is an OS command injection vulnerability. Exploitation allows a remote attacker to gain access to privileged internal functionality of the VCO host. Arista emphasizes that the compromised functionality was intended exclusively for internal use and was not supposed to be remotely accessible.

Successful exploitation results in full compromise of the orchestrator: the attacker gains control over the host, the data managed by VCO, and potentially all connected VeloCloud Edge devices.

Affected versions

  • VCO 5.2.x — versions prior to 5.2.3.14
  • VCO 6.1.x — versions prior to 6.1.3.4
  • VCO 6.4.x — versions prior to 6.4.2.4
  • VCO 7.0.x — versions prior to 7.0.0.1

Arista notes that the cloud (hosted) and dedicated versions of VCO were already patched in advance. The threat applies exclusively to on-premises deployments.

Indicators of compromise

Arista has published three IP addresses identified as sources of attacks:

  • 8.19.75.217
  • 206.72.242.124
  • 206.72.242.162

The company recommends immediately blocking these addresses and reviewing logs for requests originating from them.

Threat scope and cascading consequences

A key aspect of this vulnerability is its cascading potential. VeloCloud Orchestrator is the central management component of SD-WAN infrastructure: it is used to configure, monitor, and manage all VeloCloud Edge peripheral devices. Arista explicitly warns: “Compromise of the VCO platform may allow attackers to gain access to VeloCloud Edge devices.” This means that a single compromise of the orchestrator potentially opens access to the organization’s entire distributed network infrastructure.

Arista has confirmed that the vulnerability was discovered by an external researcher and is known to be actively exploited; however, it has not disclosed details on the scale of the attacks, the number of affected customers, or attribution of the threat.

Impact assessment

Organizations that use VeloCloud Orchestrator in on-premises mode to manage SD-WAN networks are at the highest risk. This is typical for large enterprises, telecommunications companies, and organizations with heightened data-control requirements that, for regulatory or architectural reasons, do not use the cloud version of VCO.

If no action is taken, the consequences include: complete attacker control over the orchestrator, access to configurations and credentials of all managed Edge devices, the ability to manipulate network policies and routing, as well as data leakage of information passing through the SD-WAN infrastructure.

Practical recommendations

Immediate actions:

  1. Update VCO to the fixed versions: 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1, respectively.
  2. Block IP addresses 8.19.75.217, 206.72.242.124, and 206.72.242.162 at the firewall level.
  3. Review logs of VCO web access, application logs, system logs, and database logs for requests from the specified addresses.

If immediate updating is not possible:

  • Restrict access to the VCO web interface to trusted administrative networks only.
  • Configure monitoring of inbound connections from the known malicious IP addresses.
  • Monitor outbound network activity from the VCO host for anomalies.
  • Audit recent administrator actions for unauthorized changes.

If compromise is suspected:

  • Preserve all VCO logs and file system timestamps before beginning recovery.
  • Rotate all credentials, including administrator accounts and access keys for Edge devices.
  • Check the status of all managed Edge devices.
  • Consider restoring or replacing orchestrator instances from trusted sources.

Parallel threat: Fortinet FortiOS SSL-VPN

At the same time, CISA has added to the KEV catalog the vulnerability CVE-2025-68686 (CVSS 5.3) in Fortinet FortiOS SSL-VPN. According to the Fortinet advisory, this CWE-200-type vulnerability (exposure of sensitive information) allows a remote unauthenticated attacker to bypass the patch designed to eliminate the symbolic link preservation mechanism observed in a number of post-exploitation cases. To exploit it, the attacker must first compromise the device through another file-system-level vulnerability. The patch was reportedly released by Fortinet in February 2025. The remediation deadline for U.S. federal agencies is August 10, 2026.

Organizations using Arista VeloCloud Orchestrator on-premises should treat updating as a task of the highest priority — a CVSS score of 10.0 combined with confirmed active exploitation and the cascading potential to compromise the entire SD-WAN infrastructure leaves no room for delay. If updating will take time, immediately isolate the VCO web interface from external access and block the published IOCs.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.