VCO orchestator unauth access exploited (CVE-2026-16812)
CVE-2026-16812
Actively exploited - CVE-2026-16812 critical VCO on-prem unauth access allows remote attackers full control. Patches exist for hosted/dedicated. No on-prem fix yet.
Actively exploited in the wild - CVE-2026-16812 is a critical vulnerability in VeloCloud Orchestrator (VCO) on-prem that allows an unauthenticated, remote attacker to access privileged internal functionality and gain full control of the VCO host, impacting confidentiality, integrity, and availability. This function was never intended for external access; hosted and dedicated versions have been patched ahead of this disclosure, but on-prem customers must act now.
Overview
CVE-2026-16812 is a critical security issue in the on-prem version of VMware’s VeloCloud Orchestrator. An internal API or management function, designed for local administrative use only, was exposed to the network without authentication. An attacker can exploit this by sending a crafted request to the vulnerable endpoint over the network, requiring no special privileges or user interaction. The CVSS 10.0 score reflects the severe impact: full compromise of the orchestrator and all data it manages.
Impact
Successful exploitation gives a remote, unauthenticated attacker full control of the VCO host. This means they can access, modify, or delete all orchestration data, credentials, and configurations managed by the orchestrator. The attacker could also pivot to other systems within the SD-WAN infrastructure, potentially disrupting network connectivity for all branches managed by the affected VCO. The confidentiality, integrity, and availability of the entire VeloCloud environment are at risk.
Remediation
VMware has confirmed that VeloCloud Orchestrator Hosted and Dedicated versions are already patched. Only the on-premises deployment is affected.
- Immediate Action: Disable remote access to the VCO management interface if not strictly required. Use a firewall or VPN to restrict access to trusted internal IPs only.
- Vendor Advisory: Monitor the VMware Security Response Center for an on-prem patch release. No version number is available yet; apply the fix as soon as it is released.
- Mitigation: Review VCO audit logs for unauthorized access from external IPs. Block the vulnerable API endpoint at the network perimeter if possible.
Security Insight
This incident highlights a recurring pattern in enterprise SD-WAN solutions: internal orchestration APIs exposed without authentication. Similar vulnerabilities in other orchestrators have been exploited to deploy ransomware across distributed networks. The fact that this was discovered externally and exploited before coordinated disclosure emphasizes the need for thorough internal API security reviews during development. Organizations running on-prem VCO should treat this as a wake-up call to audit all management interfaces for improper access controls.
For the latest on data breaches related to this vulnerability, see breach reports. For ongoing cybersecurity news coverage, visit security news.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application depl...
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution...
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox ...
Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull...