VeloCloud Orchestrator OS Command Injection (CVSS 10) Exploited in the Wild
A critical flaw in Arista's VeloCloud Orchestrator lets an attacker with no login take over the server that manages a company's whole SD-WAN network. Attackers are already exploiting it, and a breach can also expose the remote office equipment it controls.
- Severity
- CriticalCVSS 3.1 · 10.0
- Fix
- Fixed in 5.2.3.14Fix recorded on Aug 26, 2026
- Affected versions
- 5.2.0 to before 5.2.3.14; 6.1.0 to before 6.1.3.4; 6.4.0 to before 6.4.2.4+1 more
- Weakness
- CWE-78OS Command Injection
- Exploit likelihood
- 1.6% in 30 daysEPSS, higher than 74% of known flaws
- Affects
- VeloCloud Orchestrator On-Prem
- Exploited
- Yes, in the wildListed by CISA
- Added to CISA list
- Jul 27, 2026
- Federal fix deadline
- Jul 30, 2026
How it works
The orchestrator has a feature meant only for internal use that stayed reachable from the network anyway, and an attacker can send it specially crafted input that gets passed straight into a system command, letting the attacker run their own commands on the server.
What to do
Check your on-prem VCO version against the affected ranges in Arista Security Advisory 0144; Arista's own Hosted and Dedicated VCO instances are already patched. Update on-prem VCO now to 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1, restrict the web interface to trusted networks, block the three attacker IP addresses Arista published, and review web and backend logs for unexpected commands since no single sign of compromise covers every case.
There is no workaround that removes the risk short of patching, so treat the upgrade as urgent and confirm the running version afterward.
Technical details
Affected software: VeloCloud Orchestrator On-Premby Arista Networks
An attacker reaches the exposed internal feature on a VeloCloud Orchestrator server over the network without logging in. They send it crafted input designed to be read as an operating system command instead of ordinary data. The orchestrator runs that command, giving the attacker code execution on the machine that manages the company's SD-WAN sites and edge devices.
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- arista.com · 24364-security-advisory-0144 Mitigation Vendor Advisory
- cisa.gov · known-exploited-vulnerabilities-catalog US Government Resource
- bleepingcomputer.com · arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks BleepingComputer
- securityweek.com · critical-arista-velocloud-orchestrator-vulnerability-exploited-as-zero-day SecurityWeek