Arista has released a patch for a maximum‑severity command‑injection bug (CVE‑2026‑16812) affecting on‑premises VeloCloud Orchestrator. The flaw is actively exploited, scoring a perfect 10.0, so immediate remediation is essential.
Key Takeaways
- Arista patched CVE‑2026‑16812, a critical OS command injection flaw in VeloCloud Orchestrator.
- The vulnerability is actively exploited and scores a perfect 10.0 severity.
- Administrators must apply updates, block malicious IPs, and monitor for suspicious activity.
Arista Networks announced a patch for a maximum‑severity (CVSS 10.0) command‑injection bug (CVE‑2026‑16812) affecting on‑premises VeloCloud Orchestrator (VCO) installations. The flaw allows unauthenticated attackers to execute arbitrary operating‑system commands via the VCO web interface, compromising confidentiality, integrity, and availability of the orchestrator and the data it manages.
According to Arista’s security advisory, the vulnerability is present in VCO 5.2.x (pre‑5.2.3.14), 6.1.x (pre‑6.1.3.4), 6.4.x (pre‑6.4.2.4) and 7.0.x (pre‑7.0.0.1) on‑prem deployments. Hosted and dedicated cloud versions were already patched, and VeloCloud Gateway and Edge devices are not affected.
Historical Background
VeloCloud Orchestrator has been the central management point for SD‑WAN deployments since Arista acquired the technology in 2020. Previous CVEs have targeted peripheral components, but CVE‑2026‑16812 is the first to expose the core orchestration engine to unauthenticated remote code execution.
Why This Matters
BozokMedia analysis shows that a compromised VCO can serve as a launchpad to infiltrate edge devices, alter routing policies, and exfiltrate sensitive traffic, amplifying the impact across entire enterprise networks.
"Unpatched VCO instances act as a single point of failure, giving attackers unprecedented control over SD‑WAN infrastructure," says cybersecurity analyst Maya Patel.
Mitigation Steps
Organizations should upgrade to VCO 5.2.3.14, 6.1.3.4, 6.4.2.4 or later, restrict web‑interface access to trusted administrative networks, block the known malicious IPs (8.19.75.217, 206.72.242.124, 206.72.242.162), and monitor logs for abnormal requests or configuration changes.
Frequently Asked Questions
- Is the vulnerability present in cloud‑hosted VCO? No, hosted and dedicated cloud deployments were patched before the advisory.
- What immediate actions should I take if I suspect compromise? Preserve logs, isolate the VCO host, rotate credentials, and apply the latest patch before conducting a full forensic review.