Skip to main content
Emerging ThreatsMalware & Ransomware

Arista VeloCloud Flaw Exposes On-Premises Networks to Active Exploitation

Network operations center with a large blank screen on a workstation amidst cables and servers.

"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host," Arista warned in its advisory — an admission that the vendor says reflects active exploitation of a maximum-severity flaw tracked as CVE-2026-16812.

What CVE-2026-16812 is and why it matters

CVE-2026-16812 carries a CVSS score of 10.0 and is described by Arista as an operating system command injection vulnerability that "could pave the way for arbitrary code execution." Arista's advisory says successful exploitation "may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator." The company further noted that the vulnerable functionality "was intended to be for internal use only and is not intended to be remotely accessible."

Affected Arista VCO releases and vendor remediation

Arista said the flaw affects on-premises VeloCloud Orchestrator (VCO) releases and listed the specific impacted versions. The affected releases are:

  • VCO 5.2.x releases prior to 5.2.3.14
  • VCO 6.1.x releases prior to 6.1.3.4
  • VCO 6.4.x releases prior to 6.4.2.4
  • VCO 7.0.x releases prior to 7.0.0.1

Arista also said the issue "has already been addressed in hosted and dedicated versions of VCO in advance," indicating those deployment models were patched before the advisory for on-premises instances was released.

Indicators of compromise and Arista's operational guidance

Arista provided a short list of actionable items for operators and three IP addresses it identified as responsible for "conducting the attacks," urging customers to block them and review logs. The IoCs are:

  • 8.19.75.217
  • 206.72.242.124
  • 206.72.242.162

Where immediate updating is not possible, Arista recommended restricting access to the VCO web interface to trusted administrative networks, monitoring for access from the known malicious source IPs, checking for unexpected outbound network activity from the VCO host, and reviewing recent administrator activity for unexpected changes. The company instructed that, "If compromise is suspected, operators should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible."

Arista warned that "compromises to the VCO platform may allow attackers access to the VeloCloud Edge devices as well," and suggested post-compromise actions such as credential rotation, reviewing administrator activity, validating managed device state, and restoration or replacement of affected orchestrator instances "from trusted sources."

CISA added the flaw to the KEV catalog and federal timelines

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-16812 to its Known Exploited Vulnerabilities (KEV) catalog, which the agency uses to direct federal patching priorities. The advisory says this addition requires Federal Civilian Executive Branch (FCEB) agencies to apply the patch by July 30, 2026. The reporting also notes that federal agencies have time until August 10, 2026, to apply the patches.

Fortinet and Alibaba Fastjson entries mentioned alongside Arista

The advisory and reporting placed this development alongside two other vulnerabilities that have come under attack. CISA also added a medium-severity Fortinet FortiOS SSL-VPN vulnerability (CVE-2025-68686, CVSS 5.3) to the KEV catalog, citing evidence of active exploitation; Fortinet patched that issue in February. Separately, the critical Fastjson vulnerability CVE-2026-16723 (CVSS 9.0) in Alibaba's Fastjson library remains unpatched; developers using versions 1.2.68 through 1.2.83 are urged to "enable SafeMode or switch to a non-impacted build as soon as possible," the report states.

What this means for technologists, procurement leaders, and operators

Technologists and security teams should prioritize verifying VCO versions against the fixed releases listed by Arista, preserve relevant logs if compromise is suspected, and implement the vendor's recommended mitigations (restricting web interface access, monitoring for the listed IPs, and checking outbound traffic).

Procurement and IT asset managers should note that Arista said hosted and dedicated VCO versions were addressed in advance — an important distinction when evaluating whether a given deployment has already received the fix or requires immediate remediation.

Operators of on-prem VCO instances should prepare for post-compromise actions Arista identified: credential rotation, review of administrator activity, validation of managed device state, and restoring or replacing orchestrator instances from trusted sources if compromise is confirmed.

Arista acknowledged the vulnerability was "externally discovered and known to be actively exploited," but the company did not disclose when the issue was reported or how many customers might have been impacted. There are currently no publicly released details on exploitation methods, the scale of attacks, or the identity of those behind them. The CISA KEV listing and federal patching dates set near-term deadlines for remediation; how well those deadlines are met will determine whether the active exploitation reported by Arista becomes a broader operational crisis or a contained incident.

Original story