Critical Vulnerability

Arista VeloCloud zero-day exploited in attacks

Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. [...]

What Happened

Arista has released patches for a critical command injection vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments, tracked as CVE-2026-16812, following active exploitation in the wild. The flaw carries a maximum CVSS score of 10.0, indicating unauthenticated remote code execution with no user interaction required. Public reports confirm attackers are already leveraging this vulnerability to compromise VCO instances, marking a clear and present threat to organizations running on-premises VeloCloud infrastructure.

Why It Matters

Arista VeloCloud is widely deployed as a software-defined WAN (SD-WAN) solution, serving as the central management plane for thousands of enterprise networks globally. The Orchestrator is the administrative brain of the deployment, responsible for provisioning, monitoring, and configuring all edge devices. A full compromise of VCO grants an attacker administrative control over the entire SD-WAN fabric, including the ability to push malicious configurations, intercept traffic, or pivot into connected internal networks. For organizations relying on SD-WAN for branch connectivity and remote access, this vulnerability represents a direct path to network-wide compromise.

Technical Details

The vulnerability CVE-2026-16812 is a command injection flaw in the on-premises VCO web interface. Attackers can exploit it by sending specially crafted HTTP requests to the orchestrator, bypassing authentication and executing arbitrary operating system commands with elevated privileges. The flaw requires no user interaction and affects on-premises VCO deployments only — cloud-managed VeloCloud instances are not impacted. Arista has confirmed the vulnerability is being actively exploited, though specific indicators of compromise (IOCs) have not yet been published by the vendor. Affected versions include VCO prior to the patched release. Administrators should verify their VCO version against Arista’s advisory and apply the update immediately.

Immediate Risk

The risk is critical and time-sensitive. Attackers are actively scanning for and exploiting exposed VCO instances. An unpatched on-premises VCO provides a high-value entry point into enterprise networks, enabling lateral movement, data exfiltration, or ransomware deployment. Organizations with VCO exposed to the internet are at the highest risk. Even internally deployed VCO instances should not be considered safe, as attackers may chain this vulnerability with other initial access vectors. The window for proactive patching is closing rapidly.

Security Insight

This exploitation pattern mirrors the 2023 attack campaigns against VMware Workspace ONE Access appliances, where a maximum-severity authentication bypass was weaponized within days of disclosure. In both cases, attackers targeted the management plane of widely deployed enterprise infrastructure — not the edge devices themselves. The defensive lesson is clear: SD-WAN orchestrators, VPN concentrators, and other centralized management consoles must be treated as Tier-0 assets, segmented from the general corporate network, and never exposed to the internet. A management-plane breach in an SD-WAN environment is functionally equivalent to handing an attacker the keys to every branch office.

Further Reading

Share:

Never miss a security update

Get real-time security alerts delivered to your preferred platform.

Related News

Related Across Yazoul

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.