Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
AI-Assisted Research Finds Linux Kernel Zero-Day for Root Escalation
July 28, 2026
GhostNet: Chinese Cyber Espionage Network Linked to PLA Attacks
July 28, 2026
Tengu Mirai Botnet Reboots IoT Devices, Resists Termination Attempts
July 28, 2026
Home/CyberSecurity News/Critical Arista VeloCloud Orchestrator Zero-Day Actively Exploited
CyberSecurity News

Critical Arista VeloCloud Orchestrator Zero-Day Actively Exploited

Key Takeaways A critical command injection vulnerability (CVE-2026-16812) in Arista VeloCloud Orchestrator (VCO) on-premises deployments is under active exploitation. The flaw, rated CVSS 10.0,...

Marcus Rodriguez
Marcus Rodriguez
July 28, 2026 3 Min Read
5 0

Key Takeaways

  • A critical command injection vulnerability (CVE-2026-16812) in Arista VeloCloud Orchestrator (VCO) on-premises deployments is under active exploitation.
  • The flaw, rated CVSS 10.0, allows unauthenticated, remote attackers to execute commands without user interaction.
  • Affected on-premises versions include those prior to 5.2.3.145, 6.1.3.46, 6.4.2.4, and 7.0.0.17.
  • Arista has released patches and urges immediate upgrades; hosted and dedicated VCO environments were patched pre-disclosure.

Critical Arista VeloCloud Orchestrator Zero-Day Actively Exploited

Arista Networks has issued an urgent security alert regarding a critical command injection vulnerability, identified as CVE-2026-16812, impacting its on-premises VeloCloud Orchestrator (VCO) deployments. The vendor has confirmed that this zero-day flaw is actively being exploited in the wild, necessitating immediate action from affected organizations to apply patches and minimize exposure.

Table Of Content

  • Key Takeaways
  • Critical Arista VeloCloud Orchestrator Zero-Day Actively Exploited
  • Technical Details of the Vulnerability
  • Affected Versions and Mitigation
  • Indicators of Compromise and Remediation
  • What You Should Do

This severe vulnerability is categorized under CWE-78, which pertains to the improper neutralization of special elements used in operating system commands. It carries a maximum CVSS v3.1 score of 10.0, underscoring its critical severity and potential for widespread impact.

Technical Details of the Vulnerability

The attack vector for CVE-2026-16812 is defined as CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. This indicates that a malicious actor can exploit the flaw remotely over a network, without requiring any authentication credentials, user interaction, or complex prerequisite conditions. The ease of exploitation contributes significantly to its critical rating.

According to Arista Security Advisory 0144, the vulnerability resides within internal VCO functionalities that were not designed for remote access. Successful exploitation grants attackers access to privileged internal operations, potentially compromising the VCO host itself. This could lead to a severe breach of confidentiality, integrity, and availability for both the orchestrator and any data it manages.

Affected Versions and Mitigation

The vulnerability specifically targets VeloCloud Orchestrator on-premises installations running versions preceding 5.2.3.145, 6.1.3.46, 6.4.2.4, and 7.0.0.17. Arista has confirmed that all hosted and dedicated VCO environments received patches prior to the public disclosure of this critical vulnerability.

By default, VCO web interfaces are exposed, and no inherent product configuration can eliminate this vulnerability. As exploitation only requires network access to the VCO web interface without operator credentials, organizations are advised to restrict access to trusted administrative networks as a temporary mitigation until updates can be fully deployed.

Indicators of Compromise and Remediation

Arista has observed active attacks originating from specific IP addresses: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Defenders should block these addresses immediately and conduct thorough investigations of historical VCO logs for any related activity.

Security teams should be vigilant for unusual URL paths, encoded characters in requests, requests targeting local or internal services, and any abnormally high request volumes. Other potential indicators of compromise include unexpected outbound HTTP or HTTPS traffic from the VCO host, unauthorized configuration changes, privileged maintenance actions, command execution, file creation, database exports, or unauthorized access to credentials, certificates, or key materials.

What You Should Do

  • Upgrade Immediately: Arista strongly advises upgrading to fixed releases: VCO 5.2.3.145, 6.1.3.46, 6.4.2.4, or any later versions within the supported software branches.
  • Restrict Network Access: Limit access to VCO web interfaces to trusted administrative networks only, as a crucial interim measure until patches are applied.
  • Block Malicious IPs: Implement blocks for the identified attacker IP addresses: 8.19.75.217, 206.72.242.124, and 206.72.242.162.
  • Monitor for IoCs: Actively monitor VCO logs for indicators of compromise, including unusual URL paths, encoded characters, requests to internal services, and anomalous traffic patterns.
  • Post-Compromise Actions: If a compromise is suspected, preserve all web, application, system, database, and file system logs before remediation. Rotate all credentials, validate the states of managed VeloCloud Edge devices, and restore affected orchestrators from trusted backups if necessary.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerabilityzero-day

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Dysphoria Botnet Infects 200,000 IoT Devices, Hides C2 on Blockchain

Next Post

Critical libssh2 Vulnerabilities Let Malicious SSH Servers Corrupt Client Memory

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Arista VeloCloud Orchestrator Zero-Day Actively Exploited
July 28, 2026
Dysphoria Botnet Infects 200,000 IoT Devices, Hides C2 on Blockchain
July 28, 2026
Scammers Impersonate ShinyHunters, Blackmail Breach Victims with Fake Webcam Videos
July 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us