Arista VeloCloud CVE-2026-16812 Hits KEV, Patch Now
Arista VeloCloud Orchestrator has a CVSS 10.0 OS command injection flaw under active exploitation. CISA added it to KEV July 27. Patch on-prem deployments now.

OS command injection. CVSS 10.0. Active exploitation confirmed. That is where Arista VeloCloud Orchestrator on-prem sits right now.
CVE-2026-16812 is an OS command injection vulnerability in Arista VeloCloud Orchestrator (VCO) on-premises deployments. A remote, unauthenticated attacker can reach privileged internal functionality and compromise the VCO host — the management plane for your entire SD-WAN fabric. Everything the orchestrator sees, controls, and stores is at risk: confidentiality, integrity, and availability. CISA added it to the Known Exploited Vulnerabilities catalog on July 27, 2026. Federal agencies under BOD 26-04 have mandatory remediation deadlines; treat those as the industry floor, not a government-only concern.
What to do
Three steps, in order:
-
Identify your exposure. This affects on-premises VeloCloud Orchestrator deployments only. Cloud-hosted VCO instances managed by Arista are not affected. If you’re running on-prem VCO, you’re in scope.
-
Apply the patch. Fixed versions are available. Arista SA-0144 has the specific versions — find your current build, confirm the upgrade path, run it. Read the advisory directly; don’t rely on a summary.
-
Check for signs of compromise if patching is delayed. Exploitation is active in the wild. If you can’t patch immediately, review VCO access logs for unexpected privileged-function calls and verify that no unauthorized accounts or configurations were added. “We’ll get to it next cycle” is a less defensible position here than usual.
Priority call
CVSS 10.0, remote unauthenticated access, active exploitation, SD-WAN management plane as the target. Losing the orchestrator means losing visibility and control over every site it manages. If you have on-prem VCO in your environment, this goes to the top of your patch queue.
The JetBrains TeamCity RCE patched this week (CVE-2026-63077, CVSS 9.8) is the other critical patch to run in parallel. Both affect build and network orchestration infrastructure — the systems that, once compromised, make everything downstream easier for an attacker to reach.
Sources: Arista SA-0144, CISA KEV, The Hacker News, BleepingComputer.
- [ CRITICAL ]CVE-2026-16812Arista VeloCloud Orchestrator OS Command Injection
Found this useful? Share it.