VeloCloud Orchestrator OS Command Injection (CVSS 10) Exploited in the Wild

Published July 27, 2026 CVE-2026-16812

A critical flaw in Arista's VeloCloud Orchestrator lets an attacker with no login take over the server that manages a company's whole SD-WAN network. Attackers are already exploiting it, and a breach can also expose the remote office equipment it controls.

Severity
CriticalCVSS 3.1 · 10.0
Fix
Fixed in 5.2.3.14Fix recorded on Aug 26, 2026
Affected versions
5.2.0 to before 5.2.3.14; 6.1.0 to before 6.1.3.4; 6.4.0 to before 6.4.2.4+1 more
Weakness
CWE-78OS Command Injection
Exploit likelihood
1.6% in 30 daysEPSS, higher than 74% of known flaws
Affects
VeloCloud Orchestrator On-Prem
Exploited
Yes, in the wildListed by CISA
Added to CISA list
Jul 27, 2026
Federal fix deadline
Jul 30, 2026

How it works

The orchestrator has a feature meant only for internal use that stayed reachable from the network anyway, and an attacker can send it specially crafted input that gets passed straight into a system command, letting the attacker run their own commands on the server.

What to do

Check your on-prem VCO version against the affected ranges in Arista Security Advisory 0144; Arista's own Hosted and Dedicated VCO instances are already patched. Update on-prem VCO now to 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1, restrict the web interface to trusted networks, block the three attacker IP addresses Arista published, and review web and backend logs for unexpected commands since no single sign of compromise covers every case.

There is no workaround that removes the risk short of patching, so treat the upgrade as urgent and confirm the running version afterward.

Technical details

Affected software: VeloCloud Orchestrator On-Premby Arista Networks

An attacker reaches the exposed internal feature on a VeloCloud Orchestrator server over the network without logging in. They send it crafted input designed to be read as an operating system command instead of ordinary data. The orchestrator runs that command, giving the attacker code execution on the machine that manages the company's SD-WAN sites and edge devices.

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Changed Impact crosses a security authority boundary
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Open in FIRST.org calculator