Arista VeloCloud Orchestrator zero-day lets attackers run commands
Arista's VeloCloud Orchestrator, the tool companies use to manage their SD-WAN network gear, has a flaw that lets an attacker take commands to it without logging in. Attackers are already using it in real attacks.
- Severity
- CriticalCVSS 3.1 · 10.0
- Fix
- Fixed in 5.2.3.14
- Affected versions
- 5.2.0 to before 5.2.3.14; 6.1.0 to before 6.1.3.4; 6.4.0 to before 6.4.2.4+1 more
- Weakness
- CWE-78OS Command Injection
- Exploit likelihood
- 1.6% in 30 daysEPSS, higher than 74% of known flaws
- Affects
- VeloCloud Orchestrator On-Prem
- Exploited
- Yes, in the wildListed by CISA
- Added to CISA list
- Jul 27, 2026
- Federal fix deadline
- Jul 30, 2026
How it works
Attackers reach a privileged part of the Orchestrator that was meant to be used only internally but is exposed to the network by default, and send it commands the system runs on the underlying machine without needing any login.
What to do
Check your on-premises VCO version against the affected ranges above. VeloCloud Orchestrator Hosted and Dedicated deployments, plus VeloCloud Gateway and Edge devices, are not affected.
Update to VCO 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1 or later now, since the flaw is already being exploited. Until patched, restrict the Orchestrator web interface to admin-only networks and watch for connections from known malicious IPs, and contact Arista support if you're on an unsupported release train.
Technical details
Affected software: VeloCloud Orchestrator On-Premby Arista Networks
CVE-2026-16812 is an unauthenticated OS command injection in on-premises VeloCloud Orchestrator, CVSS 10.0. It exposes privileged functionality intended for internal use only to the network by default, with no configuration option to disable that exposure, letting a remote attacker with no VCO tenant or operator credentials reach it and inject commands the orchestrator executes. Fixed in VCO 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- arista.com · 24364-security-advisory-0144 Mitigation Vendor Advisory
- nvd.nist.gov · CVE-2026-16812 vdb entry
- cisa.gov · known-exploited-vulnerabilities-catalog US Government Resource
- securityweek.com · critical-arista-velocloud-orchestrator-vulnerability-exploited-as-zero-day SecurityWeek