Arista Patches Critical VeloCloud Zero-Day Under Active Exploitation
A perfect-10 severity command injection flaw in on-premises VeloCloud Orchestrator deployments is being weaponized against unpatched systems, prompting emergency CISA catalog listing.
Arista Networks has issued emergency patches for a critical zero-day vulnerability in its VeloCloud Orchestrator (VCO) platform that attackers are actively exploiting to compromise corporate networks.
The flaw, tracked as CVE-2026-16812, carries a maximum CVSS severity score of 10.0 and enables unauthenticated remote attackers to execute operating system commands on vulnerable VCO instances. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, signaling urgent risk to organizations running affected deployments.
Unauthenticated Access to Critical Infrastructure
VeloCloud Orchestrator serves as the centralized management platform for configuring and monitoring VeloCloud SD-WAN deployments. The vulnerability allows attackers to access privileged internal functionality and execute OS commands without any credentials.
The attack surface proved particularly dangerous because the VCO web interface is exposed by default, with no configuration option to prevent external access. This design decision left on-premises deployments vulnerable to remote exploitation without requiring any user interaction or authentication bypass.
Arista warned in its security advisory that "successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator." A compromised VCO instance could potentially grant attackers access to the VeloCloud Edge devices managed by that orchestrator, creating cascading risk across entire network infrastructures.
Affected Versions and Patch Status
The vulnerability impacts multiple VCO version branches used in production environments. Affected releases include VCO 5.2.x (versions before 5.2.3.14), 6.1.x (before 6.1.3.4), 6.4.x (before 6.4.2.4), and 7.0.x (before 7.0.0.1).
Organizations running on-premises VCO deployments must upgrade to patched versions immediately. Arista has released fixed versions across all affected branches, and CISA's catalog listing typically carries mandatory remediation timelines for federal agencies and critical infrastructure operators.
Active Exploitation Confirmed
Security researchers confirmed the vulnerability is being actively exploited in the wild, though specific details about affected organizations and attack campaigns remain limited. The combination of maximum severity, unauthenticated access, and confirmed exploitation makes this a priority-one patch for any organization operating VeloCloud SD-WAN infrastructure.
The discovery underscores ongoing risks in network management platforms that combine privileged access with internet-exposed interfaces. For SD-WAN deployments where the orchestrator controls edge devices across distributed locations, a single compromised instance could provide attackers with a foothold into geographically dispersed network infrastructure.