criticalZero-Day

Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

First seen Jul 28, 2026 · Updated Jul 28, 2026

CISA-KEVSD-WANcommand-injectionnetwork-infrastructureedge-devicepre-auth-suspected

A critical OS command injection vulnerability (CVE-2026-16812) affects Arista VeloCloud Orchestrator On-Prem, a core SD-WAN management platform. CISA has added this to its Known Exploited Vulnerabilities catalog with an unusually short 3-day remediation window, indicating active exploitation in the wild. Successful exploitation grants attackers privileged access to the orchestrator host, threatening confidentiality, integrity, and availability of the entire managed SD-WAN fabric.

Technical Analysis

CVE-2026-16812 is an OS command injection flaw in Arista VeloCloud Orchestrator (VCO) On-Prem that allows a remote attacker to inject and execute arbitrary OS-level commands, likely via improperly sanitized input passed to a system shell within a management API or web interface function. The short CISA KEV remediation window (3 days) strongly suggests active exploitation, potentially by ransomware affiliates or nation-state actors targeting network infrastructure for lateral movement and persistent access. Because VCO centrally manages edge devices across an organization's WAN, compromise could enable configuration tampering, traffic interception, or pivoting into internal networks including branch offices and cloud gateways. Organizations running AI agents or automated orchestration tools that traverse SD-WAN links managed by a compromised VCO instance could have their traffic intercepted, redirected, or manipulated, and any API keys or credentials transiting the compromised network path could be exposed to attackers, indirectly impacting agent-to-tool and agent-to-API communications.

Affected Systems

Arista VeloCloud Orchestrator On-Prem deployments (self-hosted, non-SaaS instances); specific vulnerable version ranges not disclosed in source data but organizations should assume all On-Prem VCO versions prior to the vendor's patched release are at risk.

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) published in available source data; monitor Arista security advisories and CISA KEV catalog for updates.

Remediation Steps

  1. 1

    Apply vendor patch immediately

    Update Arista VeloCloud Orchestrator On-Prem to the vendor-released fixed version as soon as available, prioritizing this due to the CISA-mandated 3-day remediation deadline.

  2. 2

    Restrict management interface exposure

    Ensure VCO administrative interfaces are not exposed to the public internet; restrict access via firewall rules, VPN, or allow-listing to trusted management networks only.

  3. 3

    Review orchestrator logs for exploitation indicators

    Audit VCO system and access logs for anomalous command execution, unexpected process spawning, or unauthorized configuration changes.

  4. 4

    Rotate credentials and API keys

    Rotate administrative credentials, API tokens, and any keys used by automated systems or agents that interact with the orchestrator or downstream managed edge devices.

  5. 5

    Segment and monitor SD-WAN traffic

    Implement network segmentation and enhanced monitoring on SD-WAN links to detect potential lateral movement or traffic interception stemming from a compromised orchestrator.

CVE / Advisory IDs

CVE-2026-16812

Industries Most Exposed

TelecommunicationsManaged Service ProvidersEnterprise IT/NetworkingFinancial ServicesHealthcareGovernmentRetail

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.