A critical security vulnerability affecting Arista VeloCloud Orchestrator (VCO) on-premises versions is being actively exploited. The flaw, identified as CVE-2026-16812 with a CVSS score of 10.0, involves an operating system command injection that can lead to arbitrary code execution.
Details of the Exploit
Arista Networks has disclosed this vulnerability, which could allow remote attackers to access sensitive internal functions, jeopardizing the security of the orchestrator and the data it manages. This issue was meant for internal use only and was not designed for remote access.
The vulnerability affects specific releases of VCO, including VCO 5.2.x before 5.2.3.14, VCO 6.1.x before 6.1.3.4, VCO 6.4.x before 6.4.2.4, and VCO 7.0.x before 7.0.0.1. While hosted and dedicated versions have been patched, Arista has not disclosed when the flaw was discovered or how many customers have been impacted.
Preventive Measures and Recommendations
Arista has provided indicators of compromise, including three IP addresses responsible for the attacks, and recommends customers block these addresses. It’s advised to examine logs for any signs of these IPs and preserve logs if a breach is suspected.
If updating to a fixed VCO release is not feasible immediately, it is recommended to restrict VCO web access to trusted networks, monitor for access from suspicious IPs, and review recent administrative activities for anomalies.
Wider Security Implications
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply the patch by July 30, 2026. This development coincides with CISA including a medium-severity vulnerability in Fortinet FortiOS SSL-VPN in its catalog, which has also been actively exploited.
Additionally, a critical flaw in Alibaba’s Fastjson library (CVE-2026-16723) is under attack and remains unpatched. Users of affected versions are urged to enable SafeMode or switch to non-impacted builds promptly.
These vulnerabilities highlight the ongoing challenges in maintaining cybersecurity and the importance of timely patch management to protect against potential threats.
