Critical Zero-Day Exploit Targets Arista VeloCloud Orchestrator (CVE-2026-16812)
Arista Networks has disclosed CVE-2026-16812, a critical command injection vulnerability (CWE-78) in on-premises VeloCloud Orchestrator (VCO) deployments, which is actively exploited in the wild. The flaw, assigned a CVSS score of 10.0, allows unauthenticated remote attackers to execute arbitrary commands on vulnerable systems without user interaction.
The vulnerability stems from improper input neutralization in VCO’s internal functionality, which was not designed for remote access. Successful exploitation could grant attackers privileged access, compromising the confidentiality, integrity, and availability of the orchestrator and its managed data. Affected versions include VCO 5.x (before 5.2.3.145), 6.1.x (before 6.1.3.46), 6.4.x (before 6.4.2.4), and 7.0.x (before 7.0.0.17). Arista has confirmed that hosted and dedicated VCO environments were patched prior to disclosure.
Exploitation requires only network access to the VCO web interface, which is exposed by default. Arista has identified three malicious IP addresses linked to attacks: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Security teams are advised to block these IPs and monitor logs for suspicious activity, including:
- Unusual URL paths or encoded characters
- Requests targeting internal services
- Unexpected outbound traffic from the VCO host
- Unauthorized configuration changes or command execution
Arista has released patched versions (5.2.3.145, 6.1.3.46, 6.4.2.4, and later) and recommends immediate upgrades. Until updates are applied, organizations should restrict VCO access to trusted administrative networks. Compromised systems should be restored from trusted sources, with credentials rotated and logs preserved for forensic analysis.
Source: https://cybersecuritynews.com/arista-velocloud-orchestrator-0-day/
Arista Networks TPRM report: https://www.rankiteo.com/company/arista-networks-inc
"id": "ari1785227106",
"linkid": "arista-networks-inc",
"type": "Vulnerability",
"date": "7/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Organizations using on-premises '
'VeloCloud Orchestrator (VCO) '
'deployments (versions 5.x '
'before 5.2.3.145, 6.1.x before '
'6.1.3.46, 6.4.x before 6.4.2.4, '
'and 7.0.x before 7.0.0.17)',
'industry': 'Networking and Cloud Services',
'name': 'Arista Networks',
'type': 'Company'}],
'attack_vector': 'Network access to the VCO web interface',
'data_breach': {'sensitivity_of_data': 'Managed data within the orchestrator'},
'description': 'Arista Networks has disclosed CVE-2026-16812, a critical '
'command injection vulnerability (CWE-78) in on-premises '
'VeloCloud Orchestrator (VCO) deployments, which is actively '
'exploited in the wild. The flaw allows unauthenticated remote '
'attackers to execute arbitrary commands on vulnerable systems '
'without user interaction, granting privileged access and '
'compromising confidentiality, integrity, and availability of '
'the orchestrator and its managed data.',
'impact': {'data_compromised': 'Confidentiality, integrity, and availability '
'of the orchestrator and managed data',
'operational_impact': 'Privileged access to the orchestrator, '
'unauthorized command execution, and '
'potential configuration changes',
'systems_affected': 'VeloCloud Orchestrator (VCO) on-premises '
'deployments'},
'initial_access_broker': {'entry_point': 'VCO web interface'},
'post_incident_analysis': {'corrective_actions': 'Patching the vulnerability '
'and restricting access to '
'trusted networks',
'root_causes': 'Improper input neutralization in '
'VCO’s internal functionality'},
'recommendations': ['Immediately upgrade to patched versions (5.2.3.145, '
'6.1.3.46, 6.4.2.4, or later)',
'Restrict VCO access to trusted administrative networks '
'until updates are applied',
'Block malicious IPs (8.19.75.217, 206.72.242.124, '
'206.72.242.162)',
'Monitor logs for suspicious activity',
'Restore compromised systems from trusted sources and '
'rotate credentials'],
'references': [{'source': 'Arista Networks Security Advisory'}],
'response': {'containment_measures': ['Block malicious IPs (8.19.75.217, '
'206.72.242.124, 206.72.242.162)',
'Restrict VCO access to trusted '
'administrative networks',
'Monitor logs for suspicious activity '
'(unusual URL paths, encoded '
'characters, requests targeting '
'internal services, unexpected outbound '
'traffic, unauthorized configuration '
'changes)'],
'enhanced_monitoring': 'Monitor logs for suspicious activity',
'remediation_measures': ['Immediate upgrades to patched versions '
'(5.2.3.145, 6.1.3.46, 6.4.2.4, or '
'later)',
'Restore compromised systems from '
'trusted sources',
'Rotate credentials',
'Preserve logs for forensic analysis']},
'title': 'Critical Zero-Day Exploit Targets Arista VeloCloud Orchestrator '
'(CVE-2026-16812)',
'type': 'Zero-Day Exploit',
'vulnerability_exploited': 'CVE-2026-16812 (CWE-78 - Improper Neutralization '
'of Special Elements used in an OS Command)'}