Critical (10.0) Actively Exploited

VCO orchestator unauth access exploited (CVE-2026-16812)

CVE-2026-16812

Actively exploited - CVE-2026-16812 critical VCO on-prem unauth access allows remote attackers full control. Patches exist for hosted/dedicated. No on-prem fix yet.

Actively exploited in the wild - CVE-2026-16812 is a critical vulnerability in VeloCloud Orchestrator (VCO) on-prem that allows an unauthenticated, remote attacker to access privileged internal functionality and gain full control of the VCO host, impacting confidentiality, integrity, and availability. This function was never intended for external access; hosted and dedicated versions have been patched ahead of this disclosure, but on-prem customers must act now.

Overview

CVE-2026-16812 is a critical security issue in the on-prem version of VMware’s VeloCloud Orchestrator. An internal API or management function, designed for local administrative use only, was exposed to the network without authentication. An attacker can exploit this by sending a crafted request to the vulnerable endpoint over the network, requiring no special privileges or user interaction. The CVSS 10.0 score reflects the severe impact: full compromise of the orchestrator and all data it manages.

Impact

Successful exploitation gives a remote, unauthenticated attacker full control of the VCO host. This means they can access, modify, or delete all orchestration data, credentials, and configurations managed by the orchestrator. The attacker could also pivot to other systems within the SD-WAN infrastructure, potentially disrupting network connectivity for all branches managed by the affected VCO. The confidentiality, integrity, and availability of the entire VeloCloud environment are at risk.

Remediation

VMware has confirmed that VeloCloud Orchestrator Hosted and Dedicated versions are already patched. Only the on-premises deployment is affected.

  • Immediate Action: Disable remote access to the VCO management interface if not strictly required. Use a firewall or VPN to restrict access to trusted internal IPs only.
  • Vendor Advisory: Monitor the VMware Security Response Center for an on-prem patch release. No version number is available yet; apply the fix as soon as it is released.
  • Mitigation: Review VCO audit logs for unauthorized access from external IPs. Block the vulnerable API endpoint at the network perimeter if possible.

Security Insight

This incident highlights a recurring pattern in enterprise SD-WAN solutions: internal orchestration APIs exposed without authentication. Similar vulnerabilities in other orchestrators have been exploited to deploy ransomware across distributed networks. The fact that this was discovered externally and exploited before coordinated disclosure emphasizes the need for thorough internal API security reviews during development. Organizations running on-prem VCO should treat this as a wake-up call to audit all management interfaces for improper access controls.

For the latest on data breaches related to this vulnerability, see breach reports. For ongoing cybersecurity news coverage, visit security news.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Related Advisories

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.