Breaking: Arista VeloCloud Orchestrator CVSS 10.0 Zero-Day Under Active Exploitation — 29 July 2026
Arista VeloCloud Orchestrator — CVSS 10.0 Zero-Day Under Active Exploitation
A maximum-severity OS command injection vulnerability in Arista VeloCloud Orchestrator (VCO) on-premises deployments is being actively exploited in the wild. Tracked as CVE-2026-16812, the flaw carries a CVSS v3.1 score of 10.0 and a CVSS v4.0 score of 10.0 — the highest possible rating on both scales.
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on July 27, 2026, giving federal agencies until July 30 to patch. That is a three-day deadline, which signals the urgency.
What Happened
Arista disclosed the vulnerability on July 27, confirming it was discovered externally and is under active exploitation. The flaw exists in VeloCloud Orchestrator on-prem versions, where a function intended for internal use is exposed to remote attackers without requiring authentication, tenant credentials, or any special configuration. By default, VCO's web interface is accessible and vulnerable. No credentials are needed.
An attacker with network access to the VCO web interface can inject OS commands, gaining full control of the orchestrator host — compromising confidentiality, integrity, and availability of the platform and all data it manages. Because VCO centrally manages VeloCloud Edge devices, compromise of the orchestrator can cascade to downstream SD-WAN edges: credential theft, configuration manipulation, and lateral movement into the managed network.
Affected Versions
- VCO 5.2.x prior to 5.2.3.14 - VCO 6.1.x prior to 6.1.3.4 - VCO 6.4.x prior to 6.4.2.4 - VCO 7.0.x prior to 7.0.0.1
Hosted and dedicated VCO deployments were patched by Arista in advance of the advisory. Only on-premises installations are affected. Arista EOS-based products, VeloCloud Edge, and VeloCloud Gateway are not affected.
IoCs and Detection
Arista published three attacker IP addresses: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Block these at the perimeter and search logs for their presence immediately. There is no single definitive indicator of compromise — look for unusual URL-like path components, encoded characters, references to local services, or high-frequency requests to internal endpoints in VCO web access logs. Review backend application logs, system logs, database logs, and file-system timestamps for anomalies. Preserve all logs before remediation.
Escalation Risk
Compromise of VCO gives attackers control over managed VeloCloud Edge devices. Check administrator activity for unexpected changes, validate device state, and rotate credentials on both the orchestrator and downstream edges. Treat an exploited VCO as a full network-layer compromise until proven otherwise.
Also on the KEV: Fortinet FortiOS SSL-VPN Bypass
CISA also added CVE-2025-68686 (CVSS 5.3) — a FortiOS SSL-VPN information exposure allowing unauthenticated attackers to bypass the patch for a symbolic link persistency mechanism. This is a secondary issue: exploitation requires prior compromise via another vulnerability at the filesystem level. Patching deadline is August 10.
So What / Action
If you run VeloCloud Orchestrator on-prem, this is an emergency. Patch to the fixed version today. If immediate patching is not possible, restrict VCO web interface access to trusted administrative networks only and monitor for the three known attacker IPs. After patching, rotate all orchestrator and edge credentials, validate device state, and review logs for signs of prior compromise. CISA's July 30 deadline is not aspirational — it reflects active exploitation right now. For organisations not running VCO, verify that no SD-WAN vendor or MSSP manages VeloCloud on your behalf — their orchestrator compromise becomes your incident.

