Arista VeloCloud Orchestrator Command Injection Exploitation (CVE-2026-16812)
First seen Jul 28, 2026 · Updated Jul 28, 2026 · CVSS 10
A maximum-severity OS command injection vulnerability (CVE-2026-16812, CVSS 10.0) in on-premises Arista VeloCloud Orchestrator (VCO) is being actively exploited in the wild. Successful exploitation allows unauthenticated or low-privilege attackers to achieve arbitrary code execution on the orchestrator, which centrally manages SD-WAN infrastructure across enterprise networks.
Technical Analysis
CVE-2026-16812 is an OS command injection flaw in on-premises deployments of Arista VeloCloud Orchestrator (VCO), the management plane for VeloCloud SD-WAN edges, allowing crafted input to be passed to system-level commands and resulting in arbitrary code execution with elevated privileges. Given the CVSS 10.0 rating, the flaw likely requires minimal or no authentication and can be reached over exposed management interfaces, making internet-facing VCO instances especially high-risk. Active exploitation indicates threat actors have already developed working exploits, potentially for initial access, lateral movement across managed WAN edges, or deployment of secondary payloads such as backdoors or ransomware. Organizations running AI agents or automation pipelines that traverse SD-WAN links managed by a compromised VCO could have their agent-to-tool or agent-to-API traffic intercepted, redirected, or manipulated, and any credentials or API keys transiting the compromised network path could be exposed to attackers.
Affected Systems
On-premises deployments of Arista VeloCloud Orchestrator (VCO); cloud-hosted/SaaS VCO instances managed directly by Arista are reportedly not affected
Indicators of Compromise
- Not disclosed in available reporting; monitor Arista security advisories for updated IOCs (exploit payloads, source IPs, webshell filenames)
Remediation Steps
- 1
Apply vendor patch immediately
Update on-premises VeloCloud Orchestrator to the patched version released by Arista as soon as it is available.
- 2
Restrict management interface exposure
Ensure VCO administrative interfaces are not exposed to the public internet; enforce access via VPN or restricted management networks.
- 3
Monitor for exploitation indicators
Review VCO logs for anomalous command execution, unexpected process spawning, or unauthorized configuration changes.
- 4
Isolate and investigate compromised orchestrators
If exploitation is suspected, isolate the affected VCO instance, rotate all associated credentials and API keys, and conduct forensic analysis before restoring service.
- 5
Apply network segmentation
Segment SD-WAN management infrastructure from critical application and agent workloads to limit blast radius if VCO is compromised.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.