A critical zero-day vulnerability, identified as CVE-2026-16812, is being actively exploited in on-premises instances of Arista Networks' VeloCloud Orchestrator (VCO). This unauthenticated OS command injection flaw carries a CVSS score of 10.0, allowing remote attackers to execute arbitrary code with privileges on the VCO host. Successful exploitation grants attackers full control over the SD-WAN control plane, enabling them to intercept traffic, modify network policies, and pivot into connected corporate networks. Arista Networks has released security patches, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to patch by July 30, 2026.
CVE-2026-16812 is an unauthenticated OS command injection vulnerability affecting the web-based management interface of the Arista VeloCloud Orchestrator. The flaw exists in a privileged internal function that was not intended to be remotely accessible. An unauthenticated attacker can send a specially crafted request to the VCO appliance to trigger this flaw, allowing them to execute arbitrary commands on the underlying operating system. The commands are executed with the privileges of the VCO application, which could lead to a full system compromise.
The attack complexity is low, and it requires no user interaction, making it highly wormable and dangerous for any internet-exposed VCO instances. The vulnerability compromises the confidentiality, integrity, and availability of the orchestrator and the entire SD-WAN fabric it manages.
Affected products are on-premises (self-hosted) installations of the Arista VeloCloud Orchestrator. Cloud-hosted and dedicated instances managed by Arista were patched prior to the advisory's release. The specific vulnerable versions are:
Arista Networks and CISA have confirmed that CVE-2026-16812 is being actively exploited in the wild. Details about the threat actors behind these attacks and the scale of exploitation have not been publicly disclosed. However, Arista has released three IP addresses associated with observed attacks. The addition to the CISA KEV catalog indicates observed, real-world exploitation and elevates the urgency for all organizations to apply patches.
A compromised VeloCloud Orchestrator represents a catastrophic failure of network security. As the centralized control and management plane for an organization's SD-WAN, an attacker with control over the VCO can:
Arista has published the following IP addresses as being linked to active exploitation campaigns.
ip_address_v48.19.75.217ip_address_v4206.72.242.124ip_address_v4206.72.242.162Security teams may want to hunt for the following patterns which could indicate related activity:
;, |, &, $(, or `./bin/sh, bash) or common reconnaissance commands (whoami, id, uname, ifconfig).D3-NTA: Network Traffic Analysis.D3-PA: Process Analysis.D3-SU: Software Update.D3-NI: Network Isolation.Applying the patches released by Arista directly remediates the vulnerability.
Restricting network access to the VCO management interface to only trusted administrative hosts reduces the attack surface.
Using a WAF or IPS to inspect traffic for command injection signatures can block exploitation attempts.
Isolating the VCO in a secure management zone limits an attacker's ability to pivot to other parts of the network if the device is compromised.
The most critical and effective countermeasure is to immediately apply the security patches provided by Arista for CVE-2026-16812. Organizations should prioritize patching internet-facing VeloCloud Orchestrator instances first, followed by internal ones. A comprehensive patch management program should be in place to track all VCO assets and their versions. Before deployment to production, patches should be tested in a staging environment to ensure they do not disrupt operations. After patching, administrators must verify that the update was successful and the new version is running. This action directly closes the vulnerability, preventing any further exploitation. Given the active exploitation and CVSS 10.0 score, this should be treated as an emergency change.
As a compensating control, especially if patching is delayed, organizations must implement strict inbound traffic filtering. Access to the VeloCloud Orchestrator's web management interface should be denied by default. Create explicit allow rules on perimeter firewalls and network ACLs to only permit traffic from a small, well-defined set of trusted IP addresses, such as a dedicated management VLAN or specific administrative jump boxes. This action drastically reduces the attack surface by preventing unauthenticated attackers on the internet from reaching the vulnerable interface. Additionally, deploying a Web Application Firewall (WAF) with rules to detect and block OS command injection patterns (e.g., shell metacharacters in URLs) can provide an additional layer of protection against this specific attack vector.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.