Critical Arista VeloCloud Orchestrator Zero-Day Actively Exploited
Key Takeaways A critical command injection vulnerability (CVE-2026-16812) in Arista VeloCloud Orchestrator (VCO) on-premises deployments is under active exploitation. The flaw, rated CVSS 10.0,...
Key Takeaways
- A critical command injection vulnerability (CVE-2026-16812) in Arista VeloCloud Orchestrator (VCO) on-premises deployments is under active exploitation.
- The flaw, rated CVSS 10.0, allows unauthenticated, remote attackers to execute commands without user interaction.
- Affected on-premises versions include those prior to 5.2.3.145, 6.1.3.46, 6.4.2.4, and 7.0.0.17.
- Arista has released patches and urges immediate upgrades; hosted and dedicated VCO environments were patched pre-disclosure.
Critical Arista VeloCloud Orchestrator Zero-Day Actively Exploited
Arista Networks has issued an urgent security alert regarding a critical command injection vulnerability, identified as CVE-2026-16812, impacting its on-premises VeloCloud Orchestrator (VCO) deployments. The vendor has confirmed that this zero-day flaw is actively being exploited in the wild, necessitating immediate action from affected organizations to apply patches and minimize exposure.
Table Of Content
This severe vulnerability is categorized under CWE-78, which pertains to the improper neutralization of special elements used in operating system commands. It carries a maximum CVSS v3.1 score of 10.0, underscoring its critical severity and potential for widespread impact.
Technical Details of the Vulnerability
The attack vector for CVE-2026-16812 is defined as CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. This indicates that a malicious actor can exploit the flaw remotely over a network, without requiring any authentication credentials, user interaction, or complex prerequisite conditions. The ease of exploitation contributes significantly to its critical rating.
According to Arista Security Advisory 0144, the vulnerability resides within internal VCO functionalities that were not designed for remote access. Successful exploitation grants attackers access to privileged internal operations, potentially compromising the VCO host itself. This could lead to a severe breach of confidentiality, integrity, and availability for both the orchestrator and any data it manages.
Affected Versions and Mitigation
The vulnerability specifically targets VeloCloud Orchestrator on-premises installations running versions preceding 5.2.3.145, 6.1.3.46, 6.4.2.4, and 7.0.0.17. Arista has confirmed that all hosted and dedicated VCO environments received patches prior to the public disclosure of this critical vulnerability.
By default, VCO web interfaces are exposed, and no inherent product configuration can eliminate this vulnerability. As exploitation only requires network access to the VCO web interface without operator credentials, organizations are advised to restrict access to trusted administrative networks as a temporary mitigation until updates can be fully deployed.
Indicators of Compromise and Remediation
Arista has observed active attacks originating from specific IP addresses: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Defenders should block these addresses immediately and conduct thorough investigations of historical VCO logs for any related activity.
Security teams should be vigilant for unusual URL paths, encoded characters in requests, requests targeting local or internal services, and any abnormally high request volumes. Other potential indicators of compromise include unexpected outbound HTTP or HTTPS traffic from the VCO host, unauthorized configuration changes, privileged maintenance actions, command execution, file creation, database exports, or unauthorized access to credentials, certificates, or key materials.
What You Should Do
- Upgrade Immediately: Arista strongly advises upgrading to fixed releases: VCO 5.2.3.145, 6.1.3.46, 6.4.2.4, or any later versions within the supported software branches.
- Restrict Network Access: Limit access to VCO web interfaces to trusted administrative networks only, as a crucial interim measure until patches are applied.
- Block Malicious IPs: Implement blocks for the identified attacker IP addresses: 8.19.75.217, 206.72.242.124, and 206.72.242.162.
- Monitor for IoCs: Actively monitor VCO logs for indicators of compromise, including unusual URL paths, encoded characters, requests to internal services, and anomalous traffic patterns.
- Post-Compromise Actions: If a compromise is suspected, preserve all web, application, system, database, and file system logs before remediation. Rotate all credentials, validate the states of managed VeloCloud Edge devices, and restore affected orchestrators from trusted backups if necessary.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.