Arista Patches CVSS 10.0 Zero-Day in VeloCloud Orchestrator Under Active Attack
CISA adds actively exploited command injection flaw to KEV catalog as administrators race to patch on-premises SD-WAN management systems.
Arista Networks has released emergency patches for a critical zero-day vulnerability in its VeloCloud Orchestrator that attackers are actively exploiting in the wild. The flaw, tracked as CVE-2026-16812, carries a maximum CVSS severity score of 10.0 and allows unauthenticated remote attackers to execute arbitrary commands on affected systems.
CISA Adds to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency has added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog. The listing carries mandatory patching requirements for federal agencies under Binding Operational Directive 22-01, with compliance timelines depending on whether the vulnerability is being actively exploited in an agency's environment.
The KEV catalog entry confirms what security researchers have been tracking: this is not a theoretical threat. Multiple sources report active exploitation in the wild, making immediate patching the only viable defense for organizations running vulnerable on-premises deployments.
On-Premises Deployments at Risk
The vulnerability affects on-premises installations of the VeloCloud Orchestrator, the central management plane for Arista's SD-WAN environments. Hosted and dedicated versions were patched separately, indicating the bug's scope is limited to self-managed deployments.
Arista has released fixes for the following version branches:
- 5.2.x before 5.2.3.14
- 6.1.x before 6.1.3.4
- 6.4.x before 6.4.2.4
- 7.0.x before 7.0.0.1
Administrators running any of these versions on-premises should prioritize patching immediately, particularly if their Orchestrator instances are exposed to the internet or accessible from compromised network segments.
Why This Matters
A CVSS 10.0 rating reflects total loss of confidentiality, integrity, and availability—the worst possible score. Because the exploit requires no authentication and can be triggered remotely, any exposed Orchestrator represents an immediate foothold for attackers.
The VeloCloud Orchestrator manages configuration and connectivity for Edge devices across corporate networks. According to The Hacker News, attackers who compromise the Orchestrator may be able to extend access to managed Edge devices. If accurate, this lateral movement capability would enable attackers to intercept traffic, pivot into internal networks, or disrupt wide-area connectivity across an entire organization.
The Patching Imperative
For security teams managing on-premises SD-WAN infrastructure, this vulnerability represents a worst-case scenario: a fully remote, unauthenticated exploit in a high-value management component with confirmed active exploitation. There is no workaround that provides adequate protection. Patching is the only path forward.
Organizations should verify their VeloCloud Orchestrator versions against the affected ranges above and apply Arista's patches as an emergency priority. Federal agencies face mandatory compliance deadlines under BOD 22-01, but the threat landscape makes this a universal imperative regardless of regulatory requirements.