Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
Summary
On July 27, 2026, Arista disclosed active exploitation of CVE-2026-16812, a critical unauthenticated OS command-injection vulnerability in on-premises VeloCloud Orchestrator (VCO). An attacker with network access to the VCO web interface can reach privileged functionality intended only for internal use and compromise the orchestrator host and the confidentiality, integrity, and availability of data it manages. Tenant or operator credentials are not required.
CISA added the flaw to the Known Exploited Vulnerabilities catalog the same day and set a July 30, 2026 remediation due date for applicable US federal systems. Arista assigned both CVSS v3.1 and v4.0 scores of 10.0 and published three source IP addresses observed conducting attacks.
Successful exploitation is a control-plane compromise, not merely a vulnerable-version finding. Preserve evidence before remediation where feasible, isolate the management interface, upgrade, rotate trust material, validate administrator and managed-device state, and restore or replace the orchestrator from trusted sources when integrity cannot be established.
Tags
- ops
- operations
- Arista
- VeloCloud
- VeloCloud Orchestrator
- SD-WAN
- CVE-2026-16812
- CISA KEV
- active exploitation
- OS command injection
- unauthenticated RCE
- network infrastructure
- management plane
- edge devices
- incident response
Why this matters
- VCO is exposed by default according to Arista; there is no product configuration that removes the vulnerable functionality. Restricting web-interface reachability reduces exposure but does not replace an upgrade.
- Exploitation requires no VCO tenant or operator credentials and can provide control over a high-trust SD-WAN orchestration host.
- Arista warns that compromise may expose VCO database contents, configuration, device inventory, credentials, certificates, and key material and may allow access to managed VeloCloud Edge devices.
- CISA's three-day due date reflects the combination of observed exploitation and potential total control of an exposed asset.
Affected and fixed releases
The advisory applies to VeloCloud Orchestrator On-Prem, formerly VeloCloud Orchestrator by Broadcom.
| Release train | Affected | Fixed / vendor direction |
|---|---|---|
| VCO 5.2.x | Before 5.2.3.14 | 5.2.3.14 or later in the 5.2 train |
| VCO 6.1.x | Before 6.1.3.4 | 6.1.3.4 or later in the 6.1 train |
| VCO 6.4.x | Before 6.4.2.4 | 6.4.2.4 or later in the 6.4 train |
| VCO 7.0.x | Before 7.0.0.1 | The affected-version table implies 7.0.0.1 is outside the vulnerable range; confirm the supported target with Arista TAC because the advisory's separate resolution list names only the 5.2, 6.1, and 6.4 fixes |
End-of-support versions were not assessed. Arista says hosted and dedicated VCO deployments were patched before disclosure and lists VeloCloud Orchestrator Hosted, VeloCloud Gateway, VeloCloud Edge, EOS-based products, and its other enumerated platforms as not affected by this vulnerability. This does not reduce the need to inspect Edge devices managed by a compromised on-premises orchestrator.
Public attack indicators
Arista reports these source addresses as observed conducting attacks:
8.19.75.217
206.72.242.124
206.72.242.162
Use them as historical investigation pivots, not as proof of compromise or a complete blocklist. Addresses can be reassigned, shared, proxied, or replaced.
Arista says there is no single definitive indicator of compromise. The vendor recommends correlating VCO web access, backend application, system, database, and filesystem evidence.
Defensive actions
Immediate containment and remediation
- Inventory on-premises VCO instances, including standby, disaster-recovery, lab, migration, and externally published management endpoints. Record version, deployment role, exposure, administrator identities, and managed Edge scope.
- Preserve VCO web access, backend application, system, database, authentication, administrator, and available filesystem-timestamp evidence before upgrades or restoration where operationally feasible.
- Restrict the VCO web interface to trusted administrative networks and block the three reported source addresses as a temporary defense-in-depth measure. Search historical telemetry before blocking.
- Upgrade to the applicable fixed release. Contact Arista TAC for unsupported trains and to reconcile the 7.0 release guidance.
- Do not treat a clean upgrade as proof that the pre-upgrade host was not compromised. If exploitation is suspected, restore or replace the instance from a trusted source after evidence collection.
Hunting
Investigate:
- requests with unusual URL-like path components, encoded characters, references to local or internal services, or abnormal request rates;
- traffic from the three reported addresses or other known-malicious sources;
- unexpected outbound HTTP or HTTPS connections from the VCO host;
- privileged maintenance operations, administrator activity, or sensitive configuration changes without an approved change record;
- unexpected command execution, file creation, database export, archive creation, or staging on the VCO host;
- access to VCO database contents, device inventory, credentials, certificates, or key material; and
- managed Edge configuration or access changes that align with suspicious VCO activity.
Absence of the published IPs is not exculpatory. Prioritize behavior and cross-log timestamp correlation.
Trust reset and downstream scoping
- Rotate VCO local and federated administrator credentials, API tokens, database credentials, certificates, private keys, device-management trust, and other secrets stored by or reachable from the orchestrator.
- Revoke active administrative sessions and review new accounts, role changes, API use, exports, backups, scheduled operations, and authentication-source changes.
- Validate managed VeloCloud Edge configuration and software state against trusted baselines. Scope network, identity, and endpoint telemetry for activity originating from the orchestrator or using credentials it stored.
- Review backup provenance before restoration so a compromised image, database, or configuration is not reintroduced.
Evidence and attribution caveats
- Arista states that the issue was discovered externally and is actively exploited; CISA independently includes it in KEV based on evidence of exploitation.
- Neither public source names an actor, victim, payload, exploit request, or post-exploitation toolkit.
- CISA lists known ransomware use as
Unknown. - The three source addresses are observed infrastructure, not durable actor attribution.
Related pages
- Arista EOS CVE-2026-7473 tunnel decapsulation exploitation
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
- Quest KACE SMA CVE-2025-32975 exploitation
Sources
- Arista Security Advisory 0144: https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
- CISA July 27 KEV alert: https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
- CISA KEV catalog: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-16812