Breaking: Arista VeloCloud Orchestrator CVSS 10.0 Zero-Day Under Active Exploitation — 28 July 2026
Arista VeloCloud Orchestrator: CVSS 10.0 Zero-Day Under Active Exploitation
Arista has disclosed a maximum-severity OS command injection vulnerability in VeloCloud Orchestrator (VCO) On-Prem that is being actively exploited in the wild. CVE-2026-16812 scores 10.0 on both CVSS v3.1 and v4.0, requires no authentication, no user interaction, and no special configuration to exploit. It affects every supported on-premises VCO release.
The flaw exists in privileged internal functionality that was never intended to be remotely accessible. Because VCO exposes its web interface by default and the vulnerable endpoint requires no tenant or operator credentials, any network-reachable orchestrator is vulnerable. An attacker who reaches the web interface can execute arbitrary commands on the VCO host, compromising the confidentiality, integrity, and availability of the orchestrator and all data it manages, including SD-WAN configuration, device credentials, and certificate material.
Arista confirmed the vulnerability was discovered externally and is under active exploitation. The company has published three attacker IP addresses observed conducting the attacks: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Organisations running VCO on-prem should block these immediately and review logs for historical access.
The blast radius extends beyond the orchestrator itself. Because VCO manages VeloCloud Edge devices across the SD-WAN fabric, a compromised orchestrator gives attackers a path to edge devices as well, including the ability to rotate credentials, modify configurations, and replace trusted orchestrator instances with attacker-controlled ones.
CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog on July 27, with a federal remediation deadline of July 30. That two-day turnaround reflects the severity.
Affected Versions
- VCO 5.2.x prior to 5.2.3.14 - VCO 6.1.x prior to 6.1.3.4 - VCO 6.4.x prior to 6.4.2.4 - VCO 7.0.x prior to 7.0.0.1
Hosted and dedicated VCO instances have already been patched by Arista in advance. On-prem deployments are the concern.
Immediate Actions
1. Patch now. Upgrade to the fixed releases listed above. If immediate patching is not possible, restrict VCO web interface access to trusted administrative networks only. 2. Block the known IOCs. Add 8.19.75.217, 206.72.242.124, and 206.72.242.162 to firewall and WAF block lists. 3. Hunt for compromise. Review VCO web access logs, backend application logs, system logs, and database logs for access from the attacker IPs or anomalous activity. Look for unexpected outbound connections, unfamiliar admin actions, and any evidence of credential or certificate access. 4. Post-remediation. Treat the orchestrator as potentially compromised. Rotate all credentials and certificates, validate the state of managed Edge devices, and consider restoring from a trusted backup rather than remediating in place.
Also on the KEV: Fortinet FortiOS SSL-VPN Bypass
CISA simultaneously added CVE-2025-68686 (CVSS 5.3) to the KEV catalog, citing active exploitation. This FortiOS SSL-VPN vulnerability allows an unauthenticated remote attacker to bypass the patch for a previous symbolic link persistence mechanism via crafted HTTP requests, but only after the device has already been compromised at the filesystem level through a separate vulnerability. The remediation deadline is August 10. If you have already patched FortiOS and do not have evidence of prior compromise, the immediate risk is lower. If you have unpatched FortiGate SSL-VPNs facing the internet, this is another reason to prioritise patching.
So What
The VeloCloud issue is the urgent one. A CVSS 10.0 zero-day in a central SD-WAN management platform, under active exploitation, with a 48-hour CISA remediation deadline, is about as serious as enterprise vulnerability situations get. The orchestrator sits at the heart of the network. Compromise of VCO is not a perimeter event; it is a control plane takeover. If you run VeloCloud on-prem, this should be the only thing your network team is doing right now.

