Arista VeloCloud zero-day exploited in attacks
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. [...]
What Happened
Arista has released patches for a critical command injection vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments, tracked as CVE-2026-16812, following active exploitation in the wild. The flaw carries a maximum CVSS score of 10.0, indicating unauthenticated remote code execution with no user interaction required. Public reports confirm attackers are already leveraging this vulnerability to compromise VCO instances, marking a clear and present threat to organizations running on-premises VeloCloud infrastructure.
Why It Matters
Arista VeloCloud is widely deployed as a software-defined WAN (SD-WAN) solution, serving as the central management plane for thousands of enterprise networks globally. The Orchestrator is the administrative brain of the deployment, responsible for provisioning, monitoring, and configuring all edge devices. A full compromise of VCO grants an attacker administrative control over the entire SD-WAN fabric, including the ability to push malicious configurations, intercept traffic, or pivot into connected internal networks. For organizations relying on SD-WAN for branch connectivity and remote access, this vulnerability represents a direct path to network-wide compromise.
Technical Details
The vulnerability CVE-2026-16812 is a command injection flaw in the on-premises VCO web interface. Attackers can exploit it by sending specially crafted HTTP requests to the orchestrator, bypassing authentication and executing arbitrary operating system commands with elevated privileges. The flaw requires no user interaction and affects on-premises VCO deployments only — cloud-managed VeloCloud instances are not impacted. Arista has confirmed the vulnerability is being actively exploited, though specific indicators of compromise (IOCs) have not yet been published by the vendor. Affected versions include VCO prior to the patched release. Administrators should verify their VCO version against Arista’s advisory and apply the update immediately.
Immediate Risk
The risk is critical and time-sensitive. Attackers are actively scanning for and exploiting exposed VCO instances. An unpatched on-premises VCO provides a high-value entry point into enterprise networks, enabling lateral movement, data exfiltration, or ransomware deployment. Organizations with VCO exposed to the internet are at the highest risk. Even internally deployed VCO instances should not be considered safe, as attackers may chain this vulnerability with other initial access vectors. The window for proactive patching is closing rapidly.
Security Insight
This exploitation pattern mirrors the 2023 attack campaigns against VMware Workspace ONE Access appliances, where a maximum-severity authentication bypass was weaponized within days of disclosure. In both cases, attackers targeted the management plane of widely deployed enterprise infrastructure — not the edge devices themselves. The defensive lesson is clear: SD-WAN orchestrators, VPN concentrators, and other centralized management consoles must be treated as Tier-0 assets, segmented from the general corporate network, and never exposed to the internet. A management-plane breach in an SD-WAN environment is functionally equivalent to handing an attacker the keys to every branch office.
Further Reading
Never miss a security update
Get real-time security alerts delivered to your preferred platform.
Related News
Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel. [...]
Hackers are exploiting the 'wp2shell' critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected
SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabiliti