Skip to content
Data Breach

Hackers Exploiting Arista VeloCloud Orchestrator 0-Day Vulnerability in the Wild

Arista Networks has issued a security advisory for CVE-2026-16812, a critical command injection vulnerability affecting on-premises VeloCloud Orchestrator deployments. The company has confirmed that this vulnerability is actively being exploited in the wild, making immediate patching and reducing ex...

· Jul 28, 2026 · 3 min read · 👁 0 views

Arista Networks has issued a security advisory for CVE-2026-16812, a critical command injection vulnerability affecting on-premises VeloCloud Orchestrator deployments.

The company has confirmed that this vulnerability is actively being exploited in the wild, making immediate patching and reducing exposure essential for affected organizations.

This vulnerability is classified as CWE-78, which refers to improper neutralization of special elements used in operating system commands. It has received a CVSS v3.1 score of 10.0, indicating a critical level of severity.

The attack vector is characterized as CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, meaning that an attacker can exploit this issue remotely over a network without the need for credentials, user interaction, or complex conditions.

Arista VeloCloud Orchestrator 0-Day Exploited

According to Arista Security Advisory 0144, the flaw exists within the internal functionality of the VeloCloud Orchestrator that was not intended to be accessible remotely.

If successfully exploited, an attacker could gain access to privileged internal functions and potentially impact the VCO host itself. This could compromise the confidentiality, integrity, and availability of both the orchestrator and the data it manages.

The issue affects VeloCloud Orchestrator on-premises installations running versions before 5.2.3.145, 6.1.3.46, 6.4.2.4, and 7.0.0.17. Arista has stated that hosted and dedicated VCO environments were patched before the public disclosure of this vulnerability.

By default, VCO web interfaces are exposed, and no product configuration can eliminate this vulnerability. Exploitation requires only network access to the VCO web interface, and operator credentials are not needed. Organizations can mitigate risk by limiting access to trusted administrative networks until updates are applied.

Arista has observed attacks originating from the following IP addresses: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Defenders should block these addresses where appropriate and investigate historical VCO logs for any related activity.

Security teams should look for unusual URL paths, encoded characters, requests involving local or internal services, and any unusually high request volumes.

Other signs of potential compromise include unexpected outbound HTTP or HTTPS traffic from the VCO host, unauthorized configuration changes, privileged maintenance actions, command execution, file creation, database exports, and access to credentials, certificates, or key materials.

Arista strongly recommends upgrading immediately to the fixed releases: VCO 5.2.3.145, 6.1.3.46, 6.4.2.4, or later versions in the supported software branches.

Organizations that suspect they have been compromised should preserve web, application, system, database, and file system logs before remediation. They should also rotate credentials, validate the states of managed VeloCloud Edge devices, and restore affected orchestrators from trusted sources if necessary.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you