Critical VeloCloud Orchestrator Vulnerability Exploited in the Wild

Security researchers have identified a critical command injection vulnerability in on-premises deployments of VeloCloud Orchestrator (VCO), which is currently being actively exploited by attackers. This flaw, designated as CVE-2026-16812, enables remote attackers to access privileged internal functions and potentially gain control over the VCO host.

VeloCloud Orchestrator serves as a centralized management platform for Software-Defined Wide Area Network (SD-WAN) environments, overseeing connected VeloCloud Edge devices, network configurations, certificates, and other sensitive operational data. A successful exploitation of this vulnerability could compromise the confidentiality, integrity, and availability of both the orchestrator and the data it manages.

Details of the Vulnerability

The vulnerability has been assigned the highest severity score of 10.0 under both CVSS v3.1 and CVSS v4.0 standards. It falls under CWE-78, which pertains to the improper neutralization of special elements used in operating system commands. Such weaknesses can allow malicious input to be interpreted as system commands, leading to unauthorized actions.

According to security advisories, the affected functionality was intended for internal use only but is accessible remotely in vulnerable on-premises VCO installations. Notably, attackers do not require VCO tenant or operator credentials to exploit this flaw; they only need network access to the VCO web interface, which is exposed by default.

The affected versions include:

  • VCO 5.2.x releases prior to 5.2.3.14
  • VCO 6.1.x releases prior to 6.1.3.4
  • VCO 6.4.x releases prior to 6.4.2.4
  • VCO 7.0.x releases prior to 7.0.0.1

Organizations should verify their specific release versions, as products not listed in the advisory are unaffected. End-of-support software versions have not been assessed. Hosted and Dedicated VCO services were patched prior to public disclosure. This issue impacts only on-premises VeloCloud Orchestrator deployments; other products such as VeloCloud Gateway, VeloCloud Edge, and hosted VCO offerings are not affected.

Recommended Actions

Administrators are urged to upgrade immediately to a fixed release. Patches are available in the following versions:

  • VCO 5.2.3.14 and later
  • VCO 6.1.3.4 and later
  • VCO 6.4.2.4 and later

Customers running unsupported release trains should contact the Arista Technical Assistance Center for upgrade guidance.

Until patches are applied, organizations should:

  • Restrict access to the VCO web interface to trusted administrative networks.
  • Monitor the VCO host for suspicious inbound requests, unexpected outbound HTTP or HTTPS traffic, unexplained configuration changes, and unusual maintenance operations.

There is no single indicator that confirms a compromise. However, administrators should investigate web requests that include unusual URL path components, encoded characters, references to local services, or unusually high request volumes. It is advisable to review backend application logs, operating system logs, database logs, and file-system timestamps for any unusual activity.

Three IP addresses have been observed in attacks: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Organizations should block these addresses as necessary and check historical logs for any connections from them.

If a compromise is suspected, incident responders should preserve relevant logs before remediation. Since an exploited orchestrator may expose managed VeloCloud Edge devices, organizations should rotate credentials, validate device states, review administrator actions, and restore affected systems only from trusted sources.

This incident underscores the critical importance of promptly addressing vulnerabilities in network management systems. Organizations must remain vigilant, ensuring that security patches are applied swiftly and that access controls are rigorously enforced to mitigate the risk of exploitation.