Jul 28, 2026
Policy

Arista VeloCloud CVE-2026-16812 patched after active exploitation

Arista says attackers are exploiting a CVSS 10.0 VeloCloud Orchestrator On-Prem flaw, and CISA has added it to its KEV catalog.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

Arista VeloCloud CVE-2026-16812 patched after active exploitation
Photo: The Register

Arista has released fixes for Arista VeloCloud CVE-2026-16812, a maximum-severity vulnerability in VeloCloud Orchestrator On-Prem that the company says is already being exploited. The bug matters because VeloCloud Orchestrator is used to manage SD-WAN deployments across branch offices, datacenters and cloud environments, putting a central control plane in scope if attackers can reach the web interface.

Arista’s security advisory describes CVE-2026-16812 as an OS command injection vulnerability with a CVSS score of 10.0. According to the company, an unauthenticated remote attacker can use the flaw to access privileged internal functions that were not intended to be available from outside the product.

The affected product is the self-hosted VeloCloud Orchestrator On-Prem. Arista said the on-premises orchestrator is exposed by default, and that there is no configuration option that removes that exposure in full. Exploitation requires access to the web interface, but Arista said no login credentials are needed.

Who needs to patch CVE-2026-16812?

Organizations running VeloCloud Orchestrator On-Prem releases earlier than the fixed versions need to upgrade. Arista said the issue does not affect customers using its hosted or dedicated VeloCloud Orchestrator services, which the company said had been patched before the advisory was published.

Fixed versions are available as VeloCloud Orchestrator 5.2.3.14, 6.1.3.4, 6.4.2.4 and 7.0.0.1. Arista urged customers on older versions to upgrade immediately.

For teams that cannot patch at once, Arista recommended limiting access to the orchestrator web interface to trusted management networks. The company also advised blocking IP addresses tied to activity it has observed, and said it published three such IP addresses. Arista did not identify the attackers, say when the exploitation began, or disclose how many customers, if any, have been compromised.

What did CISA do?

The Cybersecurity and Infrastructure Security Agency added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog after Arista confirmed real-world exploitation. CISA’s KEV list is used for vulnerabilities with evidence of active abuse. The binding remediation directive applies to US federal civilian agencies, but many private-sector security teams use the catalog to decide which edge-facing patches receive priority.

Arista warned that a successful attack could affect the confidentiality, integrity and availability of the orchestrator and the data it manages. The company also said compromise of the VeloCloud Orchestrator platform may give attackers access to VeloCloud Edge devices, which raises the risk beyond the management server itself.

The Register reported that Arista did not immediately respond to questions about the exploitation. That leaves the usual operational gaps for customers: no named threat actor, no public timeline and no disclosed victim count.

The disclosure fits a pattern security teams have had to absorb across networking equipment, VPNs, firewalls and other internet-facing enterprise infrastructure. By the time a patch is published, active exploitation may already be underway. In this case, the combination of unauthenticated access, default exposure and a CVSS 10.0 rating makes the patch cycle unusually hard to defer.

This story draws on original reporting from The Register.

More from Policy

All Policy →