If you are running an on-premises version of Arista VeloCloud Orchestrator, you need to stop what you are doing and check your systems right now. A maximum-severity vulnerability is being actively exploited in the wild, and it is as bad as it gets.
The flaw, tracked as CVE-2026-16812, carries a CVSS score of 10.0. That is the highest possible rating. It is an operating system command injection vulnerability that could allow a remote attacker to execute arbitrary code on your VCO host.
Arista released an advisory on Monday, and The Hacker News has been covering the developing story. The company acknowledged that the vulnerability was externally discovered and is known to be actively exploited. They did not say when it was disclosed or how many customers may have been impacted.
Let me walk you through everything you need to know about this Arista VeloCloud Orchestrator vulnerability and what you need to do about it.
What Is the Arista VeloCloud Orchestrator Vulnerability?
The Arista VeloCloud Orchestrator vulnerability is a command injection flaw in the on-premises version of the product. VeloCloud Orchestrator is a management platform for VeloCloud Edge devices, which are used for software-defined wide-area networking.
According to Arista's advisory, the issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. The functionality was intended for internal use only and was not meant to be remotely accessible. But attackers have found a way to reach it.
Successful exploitation of this Arista VeloCloud Orchestrator vulnerability could compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. That is the trifecta of bad outcomes.
Which Versions Are Affected?
The Arista VeloCloud Orchestrator vulnerability affects specific on-premises releases. The company says the issue has already been addressed in hosted and dedicated versions of VCO in advance. But if you are running on-premises, you need to check your version carefully.
The affected versions are:
- VCO 5.2.x releases prior to 5.2.3.14
- VCO 6.1.x releases prior to 6.1.3.4
- VCO 6.4.x releases prior to 6.4.2.4
- VCO 7.0.x releases prior to 7.0.0.1
If you are running any of these versions, you are vulnerable to this Arista VeloCloud Orchestrator vulnerability and need to patch immediately.
Is This Arista VeloCloud Orchestrator Vulnerability Being Exploited?
Yes. And that is what makes this situation urgent. Arista acknowledged that the Arista VeloCloud Orchestrator vulnerability is known to be actively exploited in the wild. The company shared a set of three IP addresses that it said were responsible for conducting the attacks.
The IP addresses are:
- 8.19.75.217
- 206.72.242.124
- 206.72.242.162
Arista is urging customers to block these IP addresses and review their logs to determine if they are present. If you see any of these addresses in your logs, you may have been targeted.
What Should You Do If You Suspect Compromise?
Arista provided specific guidance for organizations that suspect they may have been compromised by this Arista VeloCloud Orchestrator vulnerability. If compromise is suspected, operators should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation.
This is important because you need evidence for your incident response. Preserve the logs before you start fixing things. Once you have preserved the evidence, you can proceed with remediation.
What Is the Impact of This Arista VeloCloud Orchestrator Vulnerability?
The impact of the Arista VeloCloud Orchestrator vulnerability goes beyond just the orchestrator itself. Arista warned that compromises to the VCO platform may allow attackers access to the VeloCloud Edge devices as well.
This is a cascading risk. An attacker who compromises the orchestrator can potentially reach the edge devices that the orchestrator manages. This gives them access to move around your network, wreaking havoc as they go.
If you believe you’ve been compromised, Arista says you should take these actions:
- Rotate credentials
- Review administrator activity
- Validate managed device state
- Restore or replace affected orchestrator instances from trusted sources
CISA Adds the Arista VeloCloud Orchestrator Vulnerability to KEV Catalog
The urgency around this Arista VeloCloud Orchestrator vulnerability is underscored by CISA's response.
The agency has added the flaw to its Known Exploited Vulnerabilities catalog. This requires Federal Civilian Executive Branch agencies to apply the patch by July 30, 2026.
That is a tight timeline. It reflects the severity of the vulnerability and the fact that it is being actively exploited.
In Case You Cannot Patch Immediately
Arista realizes that patching is not always immediate. The following guidance was issued by the company in case you could not patch to a patched VCO release immediately.
If immediate updating is not an option, you should:
- Restrict access to the VCO web interface to trusted administrative networks
- Monitor the VCO for access from known malicious source IPs
- Check for unexpected outbound network activity from the VCO host
- Review recent administrator activity for unexpected changes
These are temporary measures. The real fix is applying the patch as soon as possible.
Another Vulnerability Added to KEV Catalog
The Arista VeloCloud Orchestrator vulnerability is not the only one CISA added to the KEV catalog. The agency also added a medium-severity security vulnerability impacting Fortinet FortiOS SSL-VPN. That flaw is tracked as CVE-2025-68686 and carries a CVSS score of 5.3.
The Fortinet vulnerability allows an exposure of sensitive information to an unauthorized actor. An attacker could bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases via crafted HTTP requests. However, Fortinet noted that an attacker would need first to have compromised the product via another vulnerability at the file system level.
There are currently no details on how the Fortinet vulnerability is being exploited in the wild, the scale of attacks, or who is behind them. Federal agencies have until August 10, 2026, to apply the patches.
The Fastjson Connection
But there’s another one which we should also mention as The Hacker News has been keeping an eye on it too. It relates to CVE-2026-16723, a critical flaw in Alibaba’s Fastjson library allowing for remote code execution (RCE) without requiring user interaction or elevated privileges. Unlike the Arista VeloCloud Orchestrator case, though, it stays unpatched.
Developers using versions 1.2.68 through 1.2.83 are urged to enable SafeMode or switch to a non-impacted build as soon as possible. The Hacker News has reported extensively on this vulnerability and will continue to update its coverage as new information becomes available.
What This Means for You
The Arista VeloCloud Orchestrator vulnerability is a reminder that on-premises software carries unique risks. Cloud-hosted versions were patched in advance, but if you are running your own instance, you are responsible for the updates.
This vulnerability is being actively exploited.
Attackers are using it right now. If you are running an affected version, you are a potential target. The patch is available. The clock is ticking.
The deadline for CISA on July 30 is more than just a recommendation. To all federal agencies, it is a must. As for everybody else, it is a clear indication that the vulnerability is too serious to be ignored.
Wrapping It Up
The Arista VeloCloud Orchestrator vulnerability is a maximum-severity flaw that is already being exploited in the wild. The CVSS score of 10.0 tells you everything you need to know about the potential impact. Command injection, remote code execution, and full compromise of the orchestrator and managed devices.
Arista has released patches. CISA has added the flaw to its KEV catalog. The indicators of compromise are known. There is no excuse to delay.
Check your version. Apply the patch. Review your logs. And if you see those IP addresses, assume you have been targeted. This is not a drill.
FAQ Section
What is the Arista VeloCloud Orchestrator vulnerability?
CVE-2026-16812 is a maximum-severity operating system command injection flaw in on-premises versions of Arista VeloCloud Orchestrator. It allows remote attackers to execute arbitrary code and compromise the orchestrator and its managed devices.
Which versions of VeloCloud Orchestrator are affected?
Affected versions include VCO 5.2.x before 5.2.3.14, VCO 6.1.x before 6.1.3.4, VCO 6.4.x before 6.4.2.4, and VCO 7.0.x before 7.0.0.1. Hosted and dedicated versions were patched in advance.
Is this Arista VeloCloud Orchestrator Vulnerability Being Exploited In-The-Wild?
Arista has confirmed that they are seeing active exploitation of this vulnerability in-the-wild, below are the IP addresses that have been identified as being used to launch these exploits:
IP Addresses Involved With Exploitation – 8.19.75.217, 206.72.242.124, 206.72.242.162
What should I do if I cannot patch immediately?
Restrict VCO web interface access to trusted administrative networks, monitor for known malicious IPs, check for unexpected outbound activity, and review administrator logs for suspicious changes.
Did CISA add this vulnerability into the agency’s KEV catalog?
Yes. The US Computer Emergency Response Team (CISA) included CVE-2026-16812 as one of the Known Exploited Vulnerabilities, whereby all the federal organizations need to apply patches before July 30, 2026.