Skip to content
feed: live
>_0dayNews
arista

Arista VeloCloud CVE-2026-16812 Hits KEV, Patch Now

Arista VeloCloud Orchestrator has a CVSS 10.0 OS command injection flaw under active exploitation. CISA added it to KEV July 27. Patch on-prem deployments now.

Arista VeloCloud CVE-2026-16812 Hits KEV, Patch Now
Photo: Rafael Minguet Delgado / Pexels · Pexels License
fuseMarisol "Fuse" Delgado·Published ·1 min read

OS command injection. CVSS 10.0. Active exploitation confirmed. That is where Arista VeloCloud Orchestrator on-prem sits right now.

CVE-2026-16812 is an OS command injection vulnerability in Arista VeloCloud Orchestrator (VCO) on-premises deployments. A remote, unauthenticated attacker can reach privileged internal functionality and compromise the VCO host — the management plane for your entire SD-WAN fabric. Everything the orchestrator sees, controls, and stores is at risk: confidentiality, integrity, and availability. CISA added it to the Known Exploited Vulnerabilities catalog on July 27, 2026. Federal agencies under BOD 26-04 have mandatory remediation deadlines; treat those as the industry floor, not a government-only concern.

What to do

Three steps, in order:

  1. Identify your exposure. This affects on-premises VeloCloud Orchestrator deployments only. Cloud-hosted VCO instances managed by Arista are not affected. If you’re running on-prem VCO, you’re in scope.

  2. Apply the patch. Fixed versions are available. Arista SA-0144 has the specific versions — find your current build, confirm the upgrade path, run it. Read the advisory directly; don’t rely on a summary.

  3. Check for signs of compromise if patching is delayed. Exploitation is active in the wild. If you can’t patch immediately, review VCO access logs for unexpected privileged-function calls and verify that no unauthorized accounts or configurations were added. “We’ll get to it next cycle” is a less defensible position here than usual.

Priority call

CVSS 10.0, remote unauthenticated access, active exploitation, SD-WAN management plane as the target. Losing the orchestrator means losing visibility and control over every site it manages. If you have on-prem VCO in your environment, this goes to the top of your patch queue.

The JetBrains TeamCity RCE patched this week (CVE-2026-63077, CVSS 9.8) is the other critical patch to run in parallel. Both affect build and network orchestration infrastructure — the systems that, once compromised, make everything downstream easier for an attacker to reach.

Sources: Arista SA-0144, CISA KEV, The Hacker News, BleepingComputer.

Related CVEs
  • [ CRITICAL ]CVE-2026-16812Arista VeloCloud Orchestrator OS Command Injection

Found this useful? Share it.