Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical VMware SD-WAN Orchestrator Vulnerability Exploited in Attacks
August 3, 2026
Critical TP-Link TL-WR940N Flaw Lets Attackers Remotely Execute Code
August 3, 2026
ModernStealer Linked to Government and Defense Data Theft
August 3, 2026
Home/CyberSecurity News/Critical VMware SD-WAN Orchestrator Vulnerability Exploited in Attacks
CyberSecurity News

Critical VMware SD-WAN Orchestrator Vulnerability Exploited in Attacks

Key Takeaways A critical command injection vulnerability, CVE-2026-16812, is under active exploitation in on-premises VeloCloud Orchestrator (VCO) deployments. The flaw carries a maximum CVSS score...

David kimber
David kimber
August 3, 2026 3 Min Read
3 0

Key Takeaways

  • A critical command injection vulnerability, CVE-2026-16812, is under active exploitation in on-premises VeloCloud Orchestrator (VCO) deployments.
  • The flaw carries a maximum CVSS score of 10.0, allowing unauthenticated remote attackers to gain privileged access and potentially control the VCO host.
  • Affected versions include specific releases across VCO 5.2.x, 6.1.x, 6.4.x, and 7.0.x series.
  • Patches are available, and immediate upgrades are strongly recommended.
  • Mitigation strategies include restricting web interface access and vigilant monitoring for suspicious activities.

Critical VMware SD-WAN Orchestrator Vulnerability Under Active Exploitation

Cybersecurity researchers are sounding the alarm over a severe command injection vulnerability, identified as CVE-2026-16812, which is being actively leveraged by attackers targeting on-premises VeloCloud Orchestrator (VCO) installations. This critical flaw grants remote attackers the ability to access privileged internal functions, potentially leading to full control over the VeloCloud Orchestrator host.

Table Of Content

  • Key Takeaways
  • Critical VMware SD-WAN Orchestrator Vulnerability Under Active Exploitation
  • Understanding the Vulnerability
  • Exploitation Details and Affected Versions
  • What You Should Do

Understanding the Vulnerability

The vulnerability has been assigned the highest possible severity rating of 10.0 on both CVSS v3.1 and CVSS v4.0 scales. It falls under CWE-78, categorized as “Improper Neutralization of Special Elements used in an OS Command.” This classification highlights a dangerous weakness where malicious input can be misinterpreted as operating system commands, enabling attackers to execute arbitrary code.

VeloCloud Orchestrator plays a central role in managing SD-WAN environments. It oversees connected VeloCloud Edge devices, network configurations, digital certificates, and other critical operational data. A successful exploitation of this vulnerability could severely compromise the confidentiality, integrity, and availability of both the orchestrator itself and all the sensitive information it manages.

Exploitation Details and Affected Versions

According to the security advisory, the vulnerable functionality was initially designed strictly for internal use. However, it is inadvertently exposed and remotely accessible in affected on-premises VCO deployments. A significant concern is that attackers do not require any VCO tenant or operator credentials to exploit this flaw. They only need network access to the VCO web interface, which is typically exposed by default.

The vulnerability impacts several specific versions of VeloCloud Orchestrator. These include VCO 5.2.x releases prior to 5.2.3.14, VCO 6.1.x releases prior to 6.1.3.4, VCO 6.4.x releases prior to 6.4.2.4, and VCO 7.0.x releases prior to 7.0.0.1. Organizations must verify their exact release versions, as only those explicitly listed in the advisory are affected. End-of-support software versions have not been evaluated. It is important to note that hosted and dedicated VCO services received patches before the public disclosure, and this issue exclusively affects on-premises VeloCloud Orchestrator deployments. Other products, such as VeloCloud Gateway, VeloCloud Edge, and various Arista EOS-based products, remain unaffected.

What You Should Do

  • Upgrade Immediately: Apply available patches without delay. Fixed versions include VCO 5.2.3.14 and later, 6.1.3.4 and later, and 6.4.2.4 and later. Customers utilizing unsupported release trains should contact the Arista Technical Assistance Center for specific upgrade guidance.
  • Restrict Network Access: Until patches are fully implemented, limit access to the VCO web interface exclusively to trusted administrative networks.
  • Monitor for Suspicious Activity: Vigilantly monitor the VCO host for any signs of compromise. This includes unexpected inbound requests, unusual outbound HTTP or HTTPS traffic, unexplained configuration changes, and abnormal maintenance operations.
  • Investigate Anomalies: Administrators should investigate web requests that contain unusual URL path components, encoded characters, references to local services, or abnormally high request volumes. Review backend application logs, operating system logs, database logs, and file-system timestamps for any unusual activity.
  • Block Malicious IP Addresses: The advisory identified three IP addresses observed in attacks: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Organizations should block these addresses at their network perimeter and review historical logs for any past connections from them.
  • Incident Response Planning: If a compromise is suspected, preserve all relevant logs before initiating remediation efforts. Given that an exploited orchestrator could expose managed VeloCloud Edge devices, it is crucial to rotate credentials, validate device states, review administrator actions, and restore affected systems only from trusted, verified sources.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical TP-Link TL-WR940N Flaw Lets Attackers Remotely Execute Code

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
XCSSET v40 Malware Steals Cookies, Runs Commands via Chrome DevTools Protocol
August 3, 2026
MacSync macOS Stealer Targets Users With Fake Claude Guide
August 3, 2026
Critical Coldcard RNG Flaw Linked to $88.6 Million Bitcoin Theft
August 3, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us