
Arista has patched a maximum-severity, unauthenticated OS command injection vulnerability, CVE-2026-16812, in the on-premises VeloCloud Orchestrator (VCO) — already under active exploitation in the wild.
TA2026212
Zero-Day: Actively Exploited
CVE-2026-16812CWE-78Arista has patched a maximum-severity flaw in the on-premises version of its VeloCloud Orchestrator (VCO), the platform organizations use to centrally manage VeloCloud SD-WAN deployments and edge devices. Tracked as CVE-2026-16812, the bug is an unauthenticated OS command injection issue that lets a remote attacker reach privileged internal functionality never meant to be exposed to the outside world, without needing any tenant or operator credentials. Arista discovered the issue through external reporting and confirms it is already being actively exploited.
| CVE | Name | Affected Product | Zero-Day | CISA KEV | Patch |
|---|---|---|---|---|---|
CVE-2026-16812 | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | Arista VeloCloud Orchestrator (VCO) | — | — | Available |
CVE-2026-16812 is an OS command injection vulnerability, classified under CWE-78 (Improper Neutralization of Special Elements used in an OS Command), affecting the on-premises deployment of Arista's VeloCloud Orchestrator. The flaw sits in internal functionality that was built for internal use only and was never intended to be reachable remotely, yet it is exposed to any network-level visitor of the VCO web interface by default.
The root cause is that VCO fails to properly sanitize input before passing it through to underlying OS commands, allowing a remote and unauthenticated attacker to inject arbitrary operating system commands. No VCO tenant or operator credentials are required, and there is no user interaction needed, making this a straightforward point-and-shoot attack path for anyone with network access to the interface. Because the exposure cannot be disabled through configuration, the only mitigation short of patching is restricting network reachability to the interface itself.
The vulnerability affects VCO on-prem releases in the 5.2.x branch prior to 5.2.3.14, the 6.1.x branch prior to 6.1.3.4, the 6.4.x branch prior to 6.4.2.4, and the 7.0.x branch before 7.0.0.1. VeloCloud Orchestrator Hosted and Dedicated deployments were already patched by Arista before the advisory was published and are not affected, and VeloCloud Gateway and VeloCloud Edge products are confirmed unaffected. End-of-support VCO release trains have not been assessed by Arista, so organizations still running them should treat their exposure as unknown and contact Arista's Technical Assistance Center for guidance. Organizations running any affected VCO on-prem release should patch to the latest available version on their respective train without delay to stay protected.
| CVE ID | Affected Products | Affected CPE | CWE ID |
|---|---|---|---|
CVE-2026-16812 |
Arista VeloCloud Orchestrator (VCO) On-Prem (5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, 7.0.x before 7.0.0.1) |
cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:* |
CWE-78 |
5.2.3.14, 6.1.3.4, or 6.4.2.4 or later depending on your release train, or move to 7.0.0.1 or later. This is the only way to close the unauthenticated command injection path, and given confirmed active exploitation, it should be treated as an emergency change.8.19.75.217, 206.72.242.124, and 206.72.242.162, and review VCO web access logs, backend application logs, and system logs for connections from these addresses or other suspicious activity, since this list is not exhaustive.T1190T1059T1068T1588| Type | Value |
|---|---|
| IPv4 | 8.19.75.217, 206.72.242.124, 206.72.242.162 |