Arista VeloCloud Orchestrator Vulnerability Exploited in Active Attacks

Arista Networks has identified a critical security vulnerability in its on-premises VeloCloud Orchestrator (VCO) software, which is currently being actively exploited. The flaw, designated as CVE-2026-16812, carries the highest severity rating with a CVSS score of 10.0. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the affected system, potentially compromising the confidentiality, integrity, and availability of the orchestrator and the data it manages.

The VeloCloud Orchestrator serves as a centralized platform for configuring, monitoring, and managing VeloCloud SD-WAN deployments and associated edge devices. The identified vulnerability enables remote attackers to access privileged internal functionalities that were intended solely for internal use and should not be remotely accessible.

Arista has released patches to address this issue in the following VCO versions:

  • VCO 5.2.x releases prior to 5.2.3.14
  • VCO 6.1.x releases prior to 6.1.3.4
  • VCO 6.4.x releases prior to 6.4.2.4
  • VCO 7.0.x releases prior to 7.0.0.1

Organizations utilizing these versions are strongly advised to update to the latest releases to mitigate the risk of exploitation. For those unable to immediately apply the patches, Arista recommends restricting access to the VCO web interface to trusted administrative networks, monitoring for access from known malicious IP addresses, and reviewing administrator activity for any unexpected changes.

Arista has identified three IP addresses associated with the ongoing attacks:

  • 8.19.75.217
  • 206.72.242.124
  • 206.72.242.162

Organizations should block these IP addresses and examine their logs for any signs of compromise. If a breach is suspected, it is crucial to preserve web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before initiating remediation efforts.

In response to the active exploitation of this vulnerability, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-16812 to its Known Exploited Vulnerabilities (KEV) catalog. Federal Civilian Executive Branch (FCEB) agencies are mandated to apply the necessary patches by July 30, 2026.

This incident underscores the critical importance of promptly addressing security vulnerabilities in network management systems. Organizations must remain vigilant, ensuring that their systems are up-to-date and that access controls are strictly enforced to prevent unauthorized exploitation of such flaws.