An unauthenticated command injection flaw in Arista's on prem VeloCloud Orchestrators — the SD WAN appliances that tie branch offices into a managed network — is under live attack; CISA's Known Exploited Vulnerabilities catalog add effectively puts
An actively exploited bug in Arista's on-prem VeloCloud Orchestrator, the SD-WAN appliance that ties branch offices into a managed network, is now on CISA's Known Exploited Vulnerabilities catalog, starting a federal remediation clock. The same KEV addition effectively puts private-sector admins on the same timer.
Tracked as CVE-2026-16812, the vulnerability is an unauthenticated OS command injection in the VCO web interface, scored 10.0 on both CVSSv3.1 and CVSSv4.0. The web UI is exposed by default and no configuration can remove that exposure; reaching it is enough, no credentials required. Only on-prem VCO is affected. Arista-hosted and dedicated VCO were patched earlier, and VeloCloud Edge devices become a downstream risk only if their orchestrator is compromised.
CISA added CVE-2026-16812 to KEV on 2026-07-27 under Binding Operational Directive 26-04, the rule that sets the federal patch deadline for civilian federal agencies. Private-sector use of the catalog is voluntary, but KEV is the de-facto "patch-or-else" marker security teams watch.
Arista confirms active exploitation and has published three attacker IPs (8.19.75.217, 206.72.242.124, and 206.72.242.162) to block at the perimeter. The vendor has not named the threat actor, given an attack start date, or shared customer impact numbers.
Fixed releases are VCO 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. Until upgrade, the only pre-fix defenses are restricting the web UI to trusted admin networks and ACL-ing the three published IPs.