
Arista has patched CVE-2026-16812, a maximum-severity (CVSS 10.0) OS command injection flaw in on-premises VeloCloud Orchestrator (VCO) — the centralized management platform organisations use to configure, monitor, and run VeloCloud SD-WAN networks. The flaw requires no authentication and no credentials: an attacker with network access to the VCO web interface can reach privileged functionality that was never meant to be externally accessible, execute arbitrary OS commands, and gain full control over the orchestrator and all configuration data it manages. Arista confirmed the vulnerability is being actively exploited in the wild.
CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog on Monday and issued a deadline of July 30, 2026 for U.S. federal civilian executive branch agencies to apply mitigations, as required under Binding Operational Directive 22-01. Patches are available for all supported on-premises VCO release trains. While patching is underway, Arista recommends restricting VCO web interface access to administrative networks, monitoring for connections from known malicious IP addresses, and reviewing recent administrator activity logs.
How to check if you’re affected
Affected versions are on-premises VeloCloud Orchestrator deployments running VCO 5.2.x before 5.2.3.14, VCO 6.1.x before 6.1.3.4, VCO 6.4.x before 6.4.2.4, or VCO 7.0.x before 7.0.0.1. VeloCloud Orchestrator Hosted and Dedicated deployments were patched separately before the advisory was published and are not vulnerable. VeloCloud Gateway and VeloCloud Edge products are also not affected. Customers running end-of-support release trains should contact Arista TAC to discuss upgrade options, as those versions have not been assessed.
