|

Arista VeloCloud Orchestrator CVE-2026-16812: CVSS 10.0 Unauthenticated Command Injection Actively Exploited — No Auth, No Workaround, CISA KEV Three-Day Deadline, Every SD-WAN Edge at Risk

PATCH NOW — CVE-2026-16812 / CISA KEV / BOD 26-04 THREE-DAY DEADLINE: (1) Determine immediately whether you run VeloCloud Orchestrator On-Prem. Hosted and dedicated VCO deployments were patched before this advisory — only on-premises deployments are affected. (2) Check your VCO version against the affected list. Fixed versions: 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. If your version is not in the affected list, you are not vulnerable. (3) Upgrade immediately — CISA’s BOD 26-04 mandates federal agencies patch within three days. Enterprise organizations should treat this on the same timeline given active exploitation. (4) End-of-support versions have not been assessed — if you are running EOL VCO, assume vulnerable and upgrade or isolate immediately. (5) Network-restrict your VCO web interface — Arista states “VCO is exposed by default. There is no configuration that can prevent the exposure.” Until patched, firewall the VCO web interface to management network IPs only. (6) Review VCO logs for anomalous privileged API calls from unexpected source IPs. (7) VeloCloud Gateway and VeloCloud Edge products are not vulnerable — the flaw is specific to the Orchestrator management plane.
Network infrastructure server rack representing Arista VeloCloud Orchestrator CVE-2026-16812 SD-WAN command injection CISA KEV 2026
No credentials. No configuration to prevent exposure. Network access to the web interface is all it takes. VCO is exposed by default — and by compromising the orchestrator, an attacker inherits management authority over every SD-WAN edge it controls. | DataWater Threat Brief, July 28, 2026

Sources: Arista Security Advisory 0144 (CVE-2026-16812, primary disclosure) · CISA Known Exploited Vulnerabilities Catalog · Bleeping Computer — “Arista patches VeloCloud Orchestrator zero-day exploited in attacks” · The Hacker News — “Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw” · SecurityWeek — “Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day” · The Register — “Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock” | CVE: CVE-2026-16812 | CVSS v3.1: 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) | CVSS v4.0: 10.0 | CWE: CWE-78 — OS Command Injection | Arista BUG: 1901675 | Authentication required: None | CISA KEV: Added July 28, 2026 — BOD 26-04 three-day deadline | Affected: VeloCloud Orchestrator On-Prem only | Fixed in: VCO 5.2.3.14, 6.1.3.4, 6.4.2.4, 7.0.0.1 | Not affected: Hosted/Dedicated VCO, VeloCloud Gateway, VeloCloud Edge

“VCO is exposed by default. There is no configuration that can prevent the exposure. A successful attack requires network access to the VCO web interface.” — Arista Security Advisory 0144

On July 28, 2026, Arista Networks published Security Advisory 0144 disclosing CVE-2026-16812 — a CVSS 10.0 unauthenticated OS command injection vulnerability in on-premises VeloCloud Orchestrator (VCO), the centralized management plane for VeloCloud SD-WAN deployments. Arista confirmed the vulnerability was discovered externally and is known to be actively exploited. CISA added it to the Known Exploited Vulnerabilities catalog the same day, triggering a three-day patch deadline for federal agencies under BOD 26-04.

The operational severity of this vulnerability exceeds what a CVSS 10.0 score alone communicates. VeloCloud Orchestrator is not a single system — it is the management plane that controls every VeloCloud SD-WAN edge device across an organization’s entire wide-area network. Compromising the orchestrator does not give an attacker access to one server. It gives them administrative authority over every branch office, data center connection, and cloud on-ramp managed by that VCO instance. Arista’s own advisory states the scope: “Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.” Bleeping Computer’s reporting goes further: compromised orchestrators may also put VeloCloud Edge devices at risk.

The attack requires no authentication, no tenant credentials, no operator credentials, no special configuration on the target, and no user interaction. The company says VCO is supposed to be exposed by default, with no configuration option that can prevent this exposure. Attackers only require network access to the VCO web interface. The CVSS vector confirms every dimension of this: Network Attack Vector, Low Complexity, No Privileges Required, No User Interaction, Changed Scope, High Confidentiality/Integrity/Availability impact — the maximum possible score on every axis.

FieldDetail
CVECVE-2026-16812
CVSS v3.1 score10.0 — Maximum (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVSS v4.0 score10.0 — Maximum
CWECWE-78 — Improper Neutralization of Special Elements in OS Command
Arista BUG ID1901675
Vulnerability typeUnauthenticated OS command injection — privileged internal functionality exposed externally
Authentication requiredNone — no VCO tenant or operator credentials needed
Attack complexityLow
User interactionNone
Network access requiredYes — to the VCO web interface only
Default exposureYes — “VCO is exposed by default. There is no configuration that can prevent the exposure.”
Affected productVeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom)
Not affectedVCO Hosted · VCO Dedicated · VeloCloud Gateway · VeloCloud Edge
Fixed versions5.2.3.14 · 6.1.3.4 · 6.4.2.4 · 7.0.0.1 and later
EOL versionsNot assessed — assume vulnerable
DiscoveryExternal — Arista does not name discoverer
Wild exploitationConfirmed — Arista acknowledges active exploitation in advisory
CISA KEVAdded July 28, 2026 — BOD 26-04 three-day federal patch deadline
Hosted/Dedicated patch statusPatched before advisory publication — on-premises only affected

What VeloCloud Orchestrator is — and why management plane compromise is categorically more severe than endpoint compromise

VeloCloud Orchestrator is the centralized brain of a VeloCloud SD-WAN deployment. SD-WAN (Software-Defined Wide Area Networking) is the architecture that most enterprises now use to connect branch offices, remote sites, data centers, and cloud environments — replacing or augmenting traditional MPLS circuits with intelligent, policy-driven routing across multiple transport links including internet, LTE, and private circuits.

In a VeloCloud SD-WAN deployment, VCO is where network administrators define routing policies, security policies, QoS rules, and application visibility across every connected site. VeloCloud Edge devices at branch offices receive their configurations from VCO and execute them — the Edge is the enforcement point, but the orchestrator is where policy originates and where the management plane lives. VeloCloud Gateways in data centers and cloud environments mediate traffic between edges and the broader network.

This architecture means that compromising VCO is not equivalent to compromising one network device. It is equivalent to compromising the management authority over every device in the entire SD-WAN fabric. An attacker with command execution on VCO can:

  • Modify routing policies across every branch office simultaneously — redirect traffic, create blackholes, or route traffic through attacker-controlled infrastructure for interception
  • Extract configuration data for every managed edge — including tunnel credentials, pre-shared keys, and topology maps of the entire WAN
  • Deploy malicious configurations to Edge devices — if the “may extend access to managed Edge devices” warning in Bleeping Computer’s reporting is confirmed, the blast radius expands from the orchestrator host to every branch office edge in the organization
  • Disrupt connectivity across the entire WAN simultaneously — a single command on VCO could take down every branch connection in the network
  • Persist via VCO configuration mechanisms — changes made through VCO propagate to edges automatically, meaning persistence established at the orchestrator level re-establishes itself at every edge on its next synchronization cycle

The “internal functionality exposed externally” detail — what it means technically

Arista’s advisory language is precise and worth parsing carefully: “This functionality was intended to be for internal use only and is not intended to be remotely accessible.” This is not a buffer overflow, a memory corruption bug, or a cryptographic weakness. It is an administrative or diagnostic API endpoint — functionality built into VCO for internal operations — that was reachable from the network without authentication because no authentication gate was placed in front of it for external access.

The CWE-78 classification (OS Command Injection) confirms that the endpoint either passes attacker-supplied input directly to an OS command, or the internal functionality it exposes includes the ability to run OS commands on the VCO host. Either way, the result is the same: an unauthenticated remote attacker can execute arbitrary commands as whatever user context the VCO web service runs under — which on an orchestrator managing sensitive network infrastructure is expected to be a highly privileged account.

The “no configuration can prevent the exposure” statement from Arista is the most operationally significant detail in the advisory. It means there is no hardening guide, no flag to set, no service to disable, no ACL within VCO itself that removes the attack surface. The only mitigations available before patching are external: network-layer access controls that restrict which source IPs can reach the VCO web interface.

The network perimeter attack arc — fifth platform actively exploited in 2026

CVE-2026-16812 is the fifth confirmed network perimeter management platform to be actively exploited in 2026, following a pattern DataWater has tracked since the beginning of the year:

  • Fortinet FortiOS / FortiGateFortiBleed: 86,644 devices, 30,000+ credential pairs, INC and Lynx ransomware (June 2026). Today CISA also added CVE-2025-68686 to KEV — a Fortinet FortiOS SSL-VPN patch bypass that enables attackers to undo the fix for the symbolic link persistence mechanism from earlier campaigns.
  • Palo Alto PAN-OSCVE-2026-0257 authentication bypass, exploited by Qilin ransomware affiliates across multiple documented intrusions (July 2026)
  • Citrix NetScalerCitrixBleed 2 (CVE-2025-5777) — seven steps from memory leak to DragonForce ransomware in under an hour (July 2026)
  • SonicWall SMA1000 — two RCE zero-days actively exploited (July 2026)
  • Arista VeloCloud Orchestrator — CVE-2026-16812, CVSS 10.0, actively exploited, CISA KEV (July 28, 2026)

The Register’s framing of the broader pattern is accurate: “Arista is far from the first vendor to issue a patch after attackers had already begun exploiting the flaw. Over the past year, a steady stream of networking gear, VPNs, firewalls, and other edge-facing enterprise software has followed the same pattern: by the time customers learn there’s a problem, somebody else has already proved it’s worth exploiting.” The pattern is systematic: network perimeter infrastructure is high-value, often under-patched relative to endpoints, and when it falls, the blast radius is measured in entire network fabrics rather than individual systems.

CISA KEV and BOD 26-04 — the three-day federal clock

CISA added CVE-2026-16812 to the Known Exploited Vulnerabilities catalog on July 28, 2026, simultaneously with Arista’s advisory publication. Under Binding Operational Directive 26-04, federal civilian agencies are required to apply mitigations within three days for KEV entries flagged as actively exploited. The three-day deadline reflects CISA’s assessment that active exploitation is ongoing and the risk of delay is unacceptable.

CISA’s KEV entry also specifically requires “Forensics Triage Requirements” — organizations patching CVE-2026-16812 must not only apply the fix but also conduct forensic triage to determine whether the vulnerability was exploited in their environment before patching. Patching closes the vulnerability; it does not remove any persistence an attacker may have established on the VCO host or on managed Edge devices during the exploitation window.

On the same day, CISA also added CVE-2025-68686 — a Fortinet FortiOS SSL-VPN vulnerability — to KEV. This is a patch bypass for the symbolic link persistency mechanism that allowed attackers to maintain read-only filesystem access on FortiOS devices even after the original vulnerabilities (CVE-2022-42475, CVE-2023-27997, CVE-2024-21762) were patched. An attacker who first compromised a FortiGate via any of those earlier CVEs and planted the symbolic link persistence mechanism retains access through CVE-2025-68686 even on a fully patched device — until this specific bypass is also remediated.

Immediate actions — the complete checklist

  1. Determine immediately whether you run VeloCloud Orchestrator On-Prem. Log into your VCO instance and check About → Version, or query your CMDB. Hosted and Dedicated VCO deployments are already patched and not vulnerable.
  2. Check your version against the fixed releases: 5.2.3.14, 6.1.3.4, 6.4.2.4, 7.0.0.1. If you are running any version below these in the 5.x, 6.1.x, 6.4.x branches, you are vulnerable. If your version is not in the affected version list at all, you are not vulnerable regardless of hardware.
  3. Upgrade immediately. This is CISA KEV with a three-day federal deadline. Enterprise organizations should treat this as a P1 emergency patch event. Coordinate with your Arista TAC or partner for upgrade support.
  4. If you cannot patch immediately: Network-restrict access to the VCO web interface at the firewall or load balancer layer. Permit only known management network source IPs. There is no VCO-internal configuration that prevents exploitation — the restriction must be external.
  5. EOL versions. If you are running an end-of-support VCO version, Arista has not assessed these — assume vulnerable. Upgrade to a supported version or isolate the VCO from external network access immediately.
  6. Conduct forensic triage as required by CISA’s KEV entry. Review VCO access logs for anomalous API calls from unexpected source IPs, particularly to internal administrative endpoints. Check for unexpected user accounts, configuration changes, or policy modifications. Review VeloCloud Edge configurations for unexpected changes that may have been propagated from a compromised orchestrator.
  7. If exploitation is suspected: Treat the VCO host as fully compromised. Assume all credentials, API keys, tunnel configurations, and topology data stored on or accessible from the VCO host are in attacker hands. Rotate all credentials, review Edge configurations, and re-establish orchestrator from a clean state before reconnecting to managed infrastructure.
  8. Separately — remediate CVE-2025-68686 on FortiOS. If you have FortiGate devices, apply the FortiOS update that addresses the patch bypass for the symbolic link persistence mechanism. Organizations that previously patched CVE-2022-42475, CVE-2023-27997, or CVE-2024-21762 may still have attacker persistence via the symbolic link mechanism if CVE-2025-68686 is not addressed.

Related DataWater Coverage — Network Perimeter Attack Arc

Sources and further reading


DataWater publishes daily cybersecurity intelligence for enterprise and government security leaders. Article #48 — July 28, 2026. Previous: Certighost CVE-2026-54121 (July 24) · ExploitGym Incident (July 23) · HollowGraph (July 20). Full archive →

Similar Posts