Arista VeloCloud Orchestrator Zero-Day (CVE-2026-16812, CVSS 10.0) Under Active Exploitation

CVSS 10.0 on the on-premises SD-WAN management box — Arista has shipped fixes, active exploitation is confirmed, and CISA has put federal agencies on a short clock.

Share
Flat white line-art of a network orchestrator console with a single open door, on a deep-teal background — the Arista VeloCloud Orchestrator command-injection zero-day.

Key Takeaways

  • On July 28, 2026 multiple outlets — The Hacker News, SecurityWeek and The Register — reported CVE-2026-16812, a CVSS 3.1 base 10.0 operating-system command injection in Arista VeloCloud Orchestrator (VCO) on-premises, is under active exploitation as a zero-day; Arista has released fixes.
  • The flaw matters to defenders because VCO is the centralized control plane for a VeloCloud SD-WAN estate, the maximum-severity rating reflects an unauthenticated network-reachable path to privileged functionality, and CISA has added the CVE to its Known Exploited Vulnerabilities catalog with a short federal patch deadline.
  • On-premises deployments are the ones in scope; per the reporting reviewed, VeloCloud Orchestrator Hosted and Dedicated (vendor-managed) deployments were remediated before disclosure and are not affected — leaving self-hosted operators to verify their build against Arista's fixed versions immediately.

A maximum-severity command-injection zero-day in the on-premises SD-WAN orchestrator, already exploited and already on CISA's clock — the defender task is verify-your-build-and-patch, today.

SANTA CLARA, CALIF. — Arista Networks has released fixes for CVE-2026-16812, a maximum-severity operating-system command-injection vulnerability in its on-premises VeloCloud Orchestrator (VCO) that, according to reporting published July 28, 2026, is already under active exploitation as a zero-day. The flaw carries a CVSS 3.1 base score of 10.0 — the highest the scale allows — and affects the centralized platform used to configure and manage a VeloCloud SD-WAN deployment.

The defender-relevant facts are narrow and urgent. As reported by The Hacker News, SecurityWeek and The Register, the vulnerability is an OS command injection in VCO on-premises, exploitation is confirmed, Arista has shipped patched builds, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a federal-agency deadline. This piece sticks to disclosure, scope and patch status; it does not reconstruct how the flaw is reached.

At a Glance
FieldDetails
CVECVE-2026-16812
SeverityCVSS 3.1 base 10.0 (maximum)
Flaw typeOperating-system command injection
Affected productArista VeloCloud Orchestrator (VCO), on-premises deployments
Not affected (per reporting)VCO Hosted and Dedicated (vendor-managed) deployments — remediated before disclosure
Fixed versionsVCO 5.2.3.14, 6.1.3.4, 6.4.2.4 and later; 7.0.0.1 and later not vulnerable
ExploitationConfirmed active exploitation as a zero-day
CISAAdded to KEV; federal patch deadline issued
Disclosure dateJuly 28, 2026

What Arista Disclosed

Arista Networks — which acquired VeloCloud from Broadcom in 2024 — has published fixes for CVE-2026-16812, an operating-system command-injection vulnerability in VeloCloud Orchestrator, the centralized management plane for a VeloCloud SD-WAN environment. Per SecurityWeek and The Hacker News, the vulnerability affects on-premises VCO deployments and carries a CVSS 3.1 base score of 10.0. A command-injection flaw at that severity is what warrants the immediacy: it describes a path by which a network-reachable request can reach privileged functionality on the appliance, which is why the reporting frames the outcome as arbitrary code execution on the orchestrator itself.

Two qualifiers keep the record accurate. This is an operating-system command injection specifically — not a generic "remote code execution" bug of unspecified type — and the maximum score reflects that the reported path does not, per the reporting reviewed, require valid VCO tenant or operator credentials to reach. The CyberSignal is not reproducing any exploitation detail; the defender-relevant facts are the product tier in scope, the severity, that patches exist, and that exploitation is already happening.

What VCO Operators Should Verify

The first task for any team running VeloCloud is a scope check, because the exposure is specific to the self-hosted tier. Per the reporting reviewed, it is the on-premises VeloCloud Orchestrator that is affected; VCO Hosted and Dedicated deployments — the ones Arista operates on the customer's behalf — were remediated before the advisory published and are reported as not affected. Operators who consume VeloCloud purely as a vendor-managed service are therefore in a very different position from those running their own orchestrator.

For on-premises operators, the verification is a version check against Arista's fixed builds. Reporting indicates the flaw is resolved in VCO 5.2.3.14, 6.1.3.4 and 6.4.2.4 and later, with the 7.0.0.1 release and later not vulnerable. Teams should confirm their exact running build against Arista's advisory rather than relying on a general "we're patched" assumption, and — because exploitation is active — treat network exposure of the VCO management interface as the immediate risk surface to constrain while patching proceeds. It is the same verify-then-patch discipline the appliance-security beat has demanded repeatedly this year, from Cisco's Catalyst SD-WAN Manager auth-bypass zero-day to the actively exploited Palo Alto GlobalProtect VPN auth bypass.

The CISA Deadline and KEV Status

The Register reports that CISA has issued deadline guidance tied to the flaw. At the time of writing, CISA has added CVE-2026-16812 to its Known Exploited Vulnerabilities (KEV) catalog and directed federal civilian agencies to remediate on the short, exploitation-driven timeline the catalog reserves for confirmed in-the-wild abuse. A KEV listing is the clearest external signal that a vulnerability is not theoretical, and it converts the internal question from "should we prioritize this" to "we are already past the point where prioritization was optional."

Although the binding order applies only to federal agencies, the KEV catalog functions as a de facto priority list well beyond government. The same escalation pattern — vendor patch, confirmed exploitation, near-immediate KEV addition with a tight clock — has recurred across this year's zero-days, including Ivanti's EPMM flaw that landed on KEV with a 10-day federal deadline. Private-sector operators running on-premises VCO should read the federal deadline as their own floor, not a ceiling.

The Maximum-Severity Command-Injection Pattern

A CVSS 10.0 is rare, and the components that produce it are worth naming plainly for a defender audience. The score reflects a vulnerability that is reachable over the network, requires little in the way of privileges or user interaction to reach the vulnerable code, and — critically — can affect the confidentiality, integrity and availability of the orchestrator and the data it manages once reached. Command injection is the mechanism the reporting identifies: a design where input that should be treated as data can instead reach the underlying operating-system shell.

For a management plane, that class of flaw is especially consequential because of what the platform sits on top of. VCO is not an endpoint; it is the console from which a fleet of SD-WAN edges is configured and monitored. The CyberSignal is deliberately not detailing the reachable path or any indicators; the defender takeaway is the category — an unauthenticated-reachable command-injection flaw in a centralized network-control platform — and the fact that a patched build already exists to close it.

Open Questions

Several specifics remain unconfirmed at publication, and The CyberSignal is not filling them in. The number of confirmed exploited environments is not established in the reporting reviewed, nor is the identity of the threat actor or actors behind the activity, nor the initial-access telemetry that would let a defender hunt precisely. Operators should watch Arista's advisory and CISA's KEV entry for updated indicators.

One item from the brief resolved during fact-checking and is worth flagging: KEV status, listed as unconfirmed at briefing, is now confirmed — CISA has added CVE-2026-16812 to the catalog with a federal remediation deadline. The affected-version detail and the not-affected status of the Hosted and Dedicated tiers also firmed up in the reporting reviewed. As Arista and CISA publish further detail, the picture will sharpen; the action in the meantime does not depend on any of the open items.


The CyberSignal Analysis

The reported facts above come from the disclosure and its reporting; what follows is The CyberSignal's editorial reading. None of the judgments below are new reported facts.

Signal 01 — The Score Is the Whole Story

A CVSS 10.0 on a management plane is about as unambiguous as vulnerability prioritization gets, and our reading is that defenders should resist the urge to over-analyze it. The combination that produces a perfect score — network-reachable, low barrier to reach the flaw, full impact on a platform that controls a fleet — is precisely the profile attackers move on first. That the flaw was exploited as a zero-day before the patch is consistent with that profile, not a surprise against it.

The practical consequence is that this is a drop-everything item for anyone running on-premises VCO, not a next-sprint one. The verification is cheap — check the build against Arista's fixed versions — and the downside of deferring it is measured against active, confirmed exploitation.

Signal 02 — Managed Tiers Bought Their Customers Time

The detail we find most instructive is the split between deployment models: the vendor-managed Hosted and Dedicated tiers were remediated before disclosure, while the self-hosted tier carries the exposure. Our assessment is that this is a clean illustration of a trade-off defenders make constantly — running your own orchestrator gives you control and also gives you the patching obligation on the vendor's worst day.

We would not read this as an argument to abandon self-hosting; plenty of organizations have sound reasons to run their own control plane. We would read it as a prompt to make sure the operational muscle matches the choice: if you own the box, you own the same-day patch, and the KEV clock is now the benchmark for how fast "same day" needs to be.

Signal 03 — Network Control Planes Are the Prize

The through-line we keep returning to this year is that centralized management appliances — SD-WAN orchestrators, VPN gateways, EDR consoles — have become a preferred target class, and Arista's VCO joins a crowded list. Our view is that the reason is structural: a single flaw in the console yields leverage over everything the console governs, which makes maximum-severity bugs in these platforms disproportionately valuable to whoever finds them first.

For defenders, the durable lesson is to treat the management plane as the crown-jewel asset it is: minimize its network exposure, watch it more closely than the edges it controls, and wire its vendor advisories directly into an emergency-patch path. The organizations that already did that will experience CVE-2026-16812 as a fast, contained version check — and that is the posture worth building toward before the next 10.0 lands.


Sources

TypeSource
ReportingThe Hacker News — Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
ReportingSecurityWeek — Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
ReportingThe Register — Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
RelatedThe CyberSignal — Cisco Catalyst SD-WAN Manager Zero-Day Exploited, No Patch
RelatedThe CyberSignal — Palo Alto GlobalProtect VPN Auth-Bypass Actively Exploited
RelatedThe CyberSignal — Ivanti EPMM Zero-Day on CISA KEV With May 10 Deadline