Arista VeloCloud Orchestrator zero-day lets attackers run commands

Published July 27, 2026 CVE-2026-16812

Arista's VeloCloud Orchestrator, the tool companies use to manage their SD-WAN network gear, has a flaw that lets an attacker take commands to it without logging in. Attackers are already using it in real attacks.

Severity
CriticalCVSS 3.1 · 10.0
Fix
Fixed in 5.2.3.14
Affected versions
5.2.0 to before 5.2.3.14; 6.1.0 to before 6.1.3.4; 6.4.0 to before 6.4.2.4+1 more
Weakness
CWE-78OS Command Injection
Exploit likelihood
1.6% in 30 daysEPSS, higher than 74% of known flaws
Affects
VeloCloud Orchestrator On-Prem
Exploited
Yes, in the wildListed by CISA
Added to CISA list
Jul 27, 2026
Federal fix deadline
Jul 30, 2026

How it works

Attackers reach a privileged part of the Orchestrator that was meant to be used only internally but is exposed to the network by default, and send it commands the system runs on the underlying machine without needing any login.

What to do

Check your on-premises VCO version against the affected ranges above. VeloCloud Orchestrator Hosted and Dedicated deployments, plus VeloCloud Gateway and Edge devices, are not affected.

Update to VCO 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1 or later now, since the flaw is already being exploited. Until patched, restrict the Orchestrator web interface to admin-only networks and watch for connections from known malicious IPs, and contact Arista support if you're on an unsupported release train.

Technical details

Affected software: VeloCloud Orchestrator On-Premby Arista Networks

CVE-2026-16812 is an unauthenticated OS command injection in on-premises VeloCloud Orchestrator, CVSS 10.0. It exposes privileged functionality intended for internal use only to the network by default, with no configuration option to disable that exposure, letting a remote attacker with no VCO tenant or operator credentials reach it and inject commands the orchestrator executes. Fixed in VCO 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Changed Impact crosses a security authority boundary
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Open in FIRST.org calculator