Arista VeloCloud Orchestrator CVE-2026-16812 Exploited

Arista VeloCloud Orchestrator CVE-2026-16812 (CVSS 10.0) is under active attack. Unauthenticated command injection lets attackers seize full SD-WAN control.

Arista VeloCloud Orchestrator CVE-2026-16812 is a maximum-severity, unauthenticated command injection flaw under active exploitation right now, and it hands an attacker control of an entire SD-WAN fabric from a single unpatched management console. CISA added it to the Known Exploited Vulnerabilities catalog on July 27, with a federal patch deadline of July 30. If your organization runs VeloCloud Orchestrator on-premises, this is not a “patch when convenient” advisory.

What Happened

Arista VeloCloud Orchestrator CVE-2026-16812 is an OS command injection vulnerability in the VeloCloud Orchestrator (VCO) On-Prem software — the self-hosted management controller that operators use to configure and monitor an entire VeloCloud SD-WAN deployment. It carries the maximum possible CVSS score of 10.0. An unauthenticated remote attacker who can reach the orchestrator’s web interface can execute arbitrary operating system commands on the host, with no credentials and no user interaction required.

The on-premises orchestrator is exposed by default, and Arista has confirmed there is no configuration option that fully removes that exposure — network reachability of the interface is the only real control point administrators have short of patching. Multiple threat-intelligence sources report active, unauthenticated scanning and exploitation against internet-reachable VCO instances, delivered via crafted HTTP POST and GET requests to the orchestrator’s exposed endpoints.

Fixes are available in VCO versions 5.2.3.14, 6.1.3.4, 6.4.2.4 and 7.0.0.1. Arista’s own hosted and dedicated VeloCloud Orchestrator service had already been patched before the public advisory — only self-managed, on-premises deployments remain exposed. CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog on July 27, 2026, giving federal civilian agencies until July 30 to remediate.

Why It Matters

An SD-WAN orchestrator is not just another appliance — it is the single management plane for every branch office, site and traffic policy the fabric controls. Compromising it does not compromise one device; it compromises the routing, traffic-steering and security posture of an entire distributed network at once. That makes CVE-2026-16812 the twelfth distinct edge-device or network-infrastructure product line DIESEC has tracked as actively exploited in 2026, following Cisco SD-WAN, Palo Alto GlobalProtect, Check Point, SonicWall (twice), Ubiquiti UniFi, OPNsense and multiple Fortinet products — the same unauthenticated, pre-auth failure mode recurring across almost every major SD-WAN and firewall vendor this year.

heise.de independently reported active attacks against both this flaw and a related Fortinet FortiOS issue in the same campaign window, giving direct confirmation from a DACH-focused outlet that exploitation is real and current, not a theoretical advisory. For DACH Mittelstand organizations and the MSPs that manage their networks, SD-WAN orchestrators are exactly the kind of centralized, high-leverage infrastructure that makes this pattern so costly when it goes wrong.

What You Should Do Now

  1. Patch immediately to VCO 5.2.3.14, 6.1.3.4, 6.4.2.4 or 7.0.0.1, whichever matches your current release branch.
  2. Verify exposure: check whether your on-premises VCO web interface is reachable from the public internet, and confirm which VCO build you are currently running.
  3. Until patched, restrict the VCO web interface to trusted management networks only, and block source IP addresses already associated with observed attacks (published in vendor and threat-intel advisories).
  4. Audit recent administrator activity and SD-WAN configuration changes for anything unexplained — routing changes, new policies or unfamiliar admin logins are the primary indicators of compromise on a controller like this.

[noch nicht unabhaengig bestaetigt] — no public technical writeup of the exact exploitation chain (beyond “command injection via the web interface”) had been independently confirmed by a second primary source at the time of writing; treat the interface itself as compromised if internet-exposed and unpatched, rather than waiting for full technical detail.

DIESEC Perspective

This is the same story DIESEC has now told a dozen times in 2026 with a dozen different vendor names in the headline: the device that centralizes control over a distributed network becomes the single point of failure that attackers go looking for first. SD-WAN orchestrators, in particular, are often deployed once and then left administratively unowned — nobody’s job description says “patch the SD-WAN controller” the way it says “patch the firewall.”

Not sure whether your SD-WAN orchestrator is reachable from the internet or running a patched build? Contact DIESEC for a rapid exposure assessment and patch verification across your network edge infrastructure.

Sources: The Hacker News | BleepingComputer
Published: 2026-07-30 | Category: Vulnerabilities & Patches | ~4 min read