Skip to main content
Emerging Threats

Arista Disrupts Zero-Day Attacks on VeloCloud Orchestrator

Network control room with large screens displaying abstracted interface.

"Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator," Arista warned — and the company says the flaw behind that warning is a maximum-severity, actively exploited zero-day.

CVE-2026-16812: a 10.0 unauthenticated command injection

Arista has patched CVE-2026-16812, described in its advisory as an unauthenticated OS command injection in on-premises VeloCloud Orchestrator (VCO). The vulnerability carries a 10.0 severity score, the maximum available. According to Arista, attackers need only network access to the VCO web interface and do not require any VCO tenant or operator credentials to exploit the flaw.

Arista's affected VeloCloud Orchestrator versions and fixes

Arista listed the specific on-premises VCO releases affected and the versions that contain the fixes:

  • VCO 5.2.x releases before 5.2.3.14
  • VCO 6.1.x releases before 6.1.3.4
  • VCO 6.4.x releases before 6.4.2.4
  • VCO 7.0.x releases before 7.0.0.1

The company states the flaw is fixed in VCO versions 5.2.3.14, 6.1.3.4, 6.4.2.4 and later, and that VCO 7.0.0.1 and later releases are not vulnerable. Arista also noted that VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory and are not affected, and that VeloCloud Gateway and VeloCloud Edge products are not vulnerable to this issue. For customers running end-of-support release trains, Arista advises contacting the Arista Technical Assistance Center to discuss upgrade options.

CISA action and mandated mitigation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and issued a Binding Operational Directive 22-01 mitigation deadline for U.S. federal civilian executive branch agencies. Agencies are required to mitigate the vulnerability by Thursday, July 30, 2026.

Arista told BleepingComputer that CVE-2026-16812 was discovered externally and is known to be actively exploited, but the company did not share when attacks began, who is behind them, or the precise exploitation method. BleepingComputer has contacted Arista with those questions.

Indicators of compromise and immediate mitigations

While patches are being deployed, Arista recommends restricting access to the VCO web interface to administrative networks, monitoring for connections from known malicious IP addresses, and reviewing recent administrator activity for unusual changes. The advisory includes the following concrete indicators of compromise and actions:

  • Block and review logs for three IP addresses Arista observed exploiting the vulnerability: 8.19.75.217, 206.72.242.124, and 206.72.242.162, while acknowledging this list is not definitive.
  • Search VCO logs for unusual web requests containing encoded characters, URL-like path components, references to local or internal services, or abnormally high request rates.
  • Look for connections from known malicious IP addresses and unexpected outbound HTTP or HTTPS traffic from the VCO host.
  • Investigate unauthorized configuration changes, privileged maintenance activity, unexpected command execution, file creation, database exports, or archive files.
  • Check for suspicious access to VCO databases, configuration data, device inventories, credentials, certificates, or cryptographic keys.

Arista warns that if compromise is suspected, organizations should preserve all logs and filesystem timestamps before remediation. The company cautions that installing the security update may not be sufficient for systems that have already been breached and notes that compromising a VeloCloud Orchestrator instance could also give attackers access to VeloCloud Edge devices.

What this means for technologists, U.S. federal agencies, and enterprise operators

  • Technologists and security teams should prioritize patching on-premises VCO instances to versions Arista lists as fixed, restrict web-interface access to administrative networks, block the three known attacker IPs, and hunt for the listed indicators of compromise.
  • U.S. federal civilian executive branch agencies must meet CISA’s Binding Operational Directive deadline of July 30, 2026, and follow the Known Exploited Vulnerabilities catalog guidance to mitigate the flaw.
  • Enterprise operators running unsupported or end-of-life VCO releases should contact Arista Technical Assistance Center to assess upgrade options and treat any VCO instance that shows signs of compromise as potentially needing full restoration or replacement rather than a simple patch.

Arista’s advisory and CISA’s catalog listing make clear the urgency: an unauthenticated, maximum-severity command injection in a central management platform is being used in the wild, and administrative access or device trust relationships managed by the orchestrator can also be at risk. Organizations that host on-premises VCO instances now face two parallel tasks — patch and hunt — because, as Arista warns, remediation may require more than an update when compromise has already occurred.

Read the original BleepingComputer report: https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/