Critical VMware SD-WAN Orchestrator Vulnerability Exploited in Attacks
Key Takeaways A critical command injection vulnerability, CVE-2026-16812, is under active exploitation in on-premises VeloCloud Orchestrator (VCO) deployments. The flaw carries a maximum CVSS score...
Key Takeaways
- A critical command injection vulnerability, CVE-2026-16812, is under active exploitation in on-premises VeloCloud Orchestrator (VCO) deployments.
- The flaw carries a maximum CVSS score of 10.0, allowing unauthenticated remote attackers to gain privileged access and potentially control the VCO host.
- Affected versions include specific releases across VCO 5.2.x, 6.1.x, 6.4.x, and 7.0.x series.
- Patches are available, and immediate upgrades are strongly recommended.
- Mitigation strategies include restricting web interface access and vigilant monitoring for suspicious activities.
Critical VMware SD-WAN Orchestrator Vulnerability Under Active Exploitation
Cybersecurity researchers are sounding the alarm over a severe command injection vulnerability, identified as CVE-2026-16812, which is being actively leveraged by attackers targeting on-premises VeloCloud Orchestrator (VCO) installations. This critical flaw grants remote attackers the ability to access privileged internal functions, potentially leading to full control over the VeloCloud Orchestrator host.
Table Of Content
Understanding the Vulnerability
The vulnerability has been assigned the highest possible severity rating of 10.0 on both CVSS v3.1 and CVSS v4.0 scales. It falls under CWE-78, categorized as “Improper Neutralization of Special Elements used in an OS Command.” This classification highlights a dangerous weakness where malicious input can be misinterpreted as operating system commands, enabling attackers to execute arbitrary code.
VeloCloud Orchestrator plays a central role in managing SD-WAN environments. It oversees connected VeloCloud Edge devices, network configurations, digital certificates, and other critical operational data. A successful exploitation of this vulnerability could severely compromise the confidentiality, integrity, and availability of both the orchestrator itself and all the sensitive information it manages.
Exploitation Details and Affected Versions
According to the security advisory, the vulnerable functionality was initially designed strictly for internal use. However, it is inadvertently exposed and remotely accessible in affected on-premises VCO deployments. A significant concern is that attackers do not require any VCO tenant or operator credentials to exploit this flaw. They only need network access to the VCO web interface, which is typically exposed by default.
The vulnerability impacts several specific versions of VeloCloud Orchestrator. These include VCO 5.2.x releases prior to 5.2.3.14, VCO 6.1.x releases prior to 6.1.3.4, VCO 6.4.x releases prior to 6.4.2.4, and VCO 7.0.x releases prior to 7.0.0.1. Organizations must verify their exact release versions, as only those explicitly listed in the advisory are affected. End-of-support software versions have not been evaluated. It is important to note that hosted and dedicated VCO services received patches before the public disclosure, and this issue exclusively affects on-premises VeloCloud Orchestrator deployments. Other products, such as VeloCloud Gateway, VeloCloud Edge, and various Arista EOS-based products, remain unaffected.
What You Should Do
- Upgrade Immediately: Apply available patches without delay. Fixed versions include VCO 5.2.3.14 and later, 6.1.3.4 and later, and 6.4.2.4 and later. Customers utilizing unsupported release trains should contact the Arista Technical Assistance Center for specific upgrade guidance.
- Restrict Network Access: Until patches are fully implemented, limit access to the VCO web interface exclusively to trusted administrative networks.
- Monitor for Suspicious Activity: Vigilantly monitor the VCO host for any signs of compromise. This includes unexpected inbound requests, unusual outbound HTTP or HTTPS traffic, unexplained configuration changes, and abnormal maintenance operations.
- Investigate Anomalies: Administrators should investigate web requests that contain unusual URL path components, encoded characters, references to local services, or abnormally high request volumes. Review backend application logs, operating system logs, database logs, and file-system timestamps for any unusual activity.
- Block Malicious IP Addresses: The advisory identified three IP addresses observed in attacks: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Organizations should block these addresses at their network perimeter and review historical logs for any past connections from them.
- Incident Response Planning: If a compromise is suspected, preserve all relevant logs before initiating remediation efforts. Given that an exploited orchestrator could expose managed VeloCloud Edge devices, it is crucial to rotate credentials, validate device states, review administrator actions, and restore affected systems only from trusted, verified sources.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.