Skip to content
vulnerabilityCVECritical Infrastructureendpoint-securityVulnerability Research

CVSS 10.0 Flaw in Arista VeloCloud Orchestrator Under Active Exploitation: Patch Immediately

3 min read
Share

Actively exploited | CVSS 10.0 | CISA KEV added 2026-07-27 | FCEB deadline 2026-08-10

CVE-2026-16812 is a CVSS 10.0 unauthenticated OS command injection vulnerability in Arista Networks' VeloCloud SD-WAN Orchestrator. CISA added it to the Known Exploited Vulnerabilities catalog on July 27, 2026, with a remediation deadline of August 10, 2026, for all federal agencies. The vulnerability requires no authentication and allows a remote attacker to execute arbitrary operating system commands on the VeloCloud Orchestrator server.

What the vulnerability does

VeloCloud Orchestrator is the centralized management plane for Arista's SD-WAN deployment. It controls WAN policy, routing configurations, and device onboarding for all VeloCloud Edge appliances in an organization's deployment. Compromise of the Orchestrator gives an attacker effective control over the organization's entire SD-WAN fabric: routing policies can be altered to redirect traffic, Edge devices can be reconfigured to hairpin traffic through attacker-controlled paths, and configuration backups containing network secrets become accessible.

The injection point is in a component of the Orchestrator's web-facing API. Because the flaw requires no authentication, any attacker with network access to the Orchestrator's management interface can reach it. Internet-exposed Orchestrator interfaces are at the highest immediate risk, but internal-only deployments are not safe: any attacker who has already gained a foothold inside the network perimeter can pivot to exploit this.

Affected and fixed versions

Arista has released patches across all supported VeloCloud Orchestrator branches. Organizations running VCO 5.x should upgrade to 5.2.3.14 or later. Organizations on the 6.1.x branch should reach 6.1.3.4 or later. Organizations on the 6.4.x branch should reach 6.4.2.4 or later. Organizations already on the 7.x branch should upgrade to 7.0.0.1 or later. All versions below these thresholds in each respective branch are vulnerable.

Why SD-WAN orchestrators are high-value targets

SD-WAN orchestrators represent an underappreciated category of network infrastructure risk. Unlike traditional firewalls or routers, orchestrators often have both management-plane internet exposure and deep trust over every device they manage. A compromised orchestrator does not just expose configuration data: it provides an attacker with an authenticated, trusted channel to every Edge device in the deployment, which may span dozens of branch offices. Nation-state actors and ransomware operators have both demonstrated sustained interest in network infrastructure management planes as initial access vectors.

Immediate actions

Patch to a fixed version as the top priority. If patching cannot be completed immediately, restrict network access to the VeloCloud Orchestrator management interface using firewall rules or access control lists. The interface should not be reachable from the public internet under any circumstances: place it behind a VPN or jump server with strong authentication if it is not already. Review Orchestrator logs for unexpected API calls or configuration changes, particularly any that occurred in the weeks prior to today, as active exploitation suggests some organizations may already be compromised.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you are securing enterprise SD-WAN or want help prioritizing your KEV remediation backlog.

Related articles