🚨 CRITICAL ALERT: Active Zero-Day Exploits
Arista VeloCloud Orchestrator (VCO) on-premises is facing a critical, actively exploited vulnerability that allows remote attackers to reach privileged internal functionality and potentially compromise the orchestrator host and managed data. CVE-2026-16812 carries a CVSS 10.0 score and has been added to the CISA KEV catalog, indicating real-world exploitation is underway.[1][2][7]
Critical Vulnerabilities (CVSS >= 8.0)
- CVE-2026-16812 (CVSS: 10.0): OS command injection in VeloCloud Orchestrator on-premises can allow a remote attacker to access internal administrative functionality, execute arbitrary commands, and impact the confidentiality, integrity, and availability of the orchestrator and its managed data. Arista states the exposed functionality was intended for internal use only, and the issue is known to be actively exploited. Hosted and Dedicated VCO versions were patched in advance of the advisory. View NVD | CISA KEV
⚡ Immediate Actions Required
Patch VCO on-premises immediately and treat any unpatched instance as a high-risk exposure. Because the flaw is actively exploited and requires no tenant or operator credentials, organizations should assume internet-exposed or broadly reachable management interfaces are at immediate risk.[2][3][7]
Restrict network access to the VCO web interface to trusted administrative sources only, and remove any unnecessary exposure to the internet or untrusted internal networks.[2][6]
Hunt for compromise by reviewing VCO host activity for unexpected outbound HTTP/HTTPS connections, unapproved configuration changes, unusual command execution, file creation, database export activity, and archive artifacts.[2]
Assess potential impact on SD-WAN configurations, credentials, certificates, key material, device inventory, and orchestration data managed by VCO, since exploitation may expose or alter this information.[2][6]
Prioritize remediation now if you operate VeloCloud Orchestrator on-premises; CISA KEV listing means this issue is not theoretical and should be handled as an active intrusion risk.[1][7]

