Arista VeloCloud Orchestrator CVE-2026-16812: CVSS 10.0 Unauthenticated Command Injection Actively Exploited — No Auth, No Workaround, CISA KEV Three-Day Deadline, Every SD-WAN Edge at Risk
Arista Networks confirmed CVE-2026-16812 — a CVSS 10.0 unauthenticated OS command injection vulnerability in VeloCloud Orchestrator On-Prem — is actively exploited. CISA added it to KEV with a three-day BOD 26-04 deadline. No authentication required. No configuration prevents exposure. VCO is exposed by default. Compromising the orchestrator gives an attacker management authority over every SD-WAN edge it controls. Fixed in VCO 5.2.3.14, 6.1.3.4, 6.4.2.4, 7.0.0.1. The fifth network perimeter platform actively exploited in 2026.
