CVE-2026-16812 — Arista VeloCloud Orchestrator Under Active Attack
Arista Networks makes networking equipment and software used by enterprises to manage wide-area networks across multiple office locations. Their VeloCloud Orchestrator (VCO) is the central control platform that manages all of those connected sites from one place.
That platform has a CVSS 10.0 flaw being actively exploited right now, according to The Hacker News. The vulnerability is an OS command injection flaw — meaning an attacker can send specially crafted requests to the VCO web interface and have the server execute system-level commands as if they typed them directly into the machine. No login required.
Arista confirmed the flaw was discovered externally and is already being weaponised. The company shared three IP addresses actively involved in the attacks: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Block these immediately if you manage a VCO instance.
What makes this particularly serious: a compromised orchestrator can give attackers a path into every VeloCloud Edge device it manages — potentially every branch office connected to the network.
Affected on-premises versions include VCO 5.2.x, 6.1.x, 6.4.x, and 7.0.x before their respective fixed releases. Cloud-hosted versions have already been patched.
CISA added this to its Known Exploited Vulnerabilities catalog, requiring federal civilian agencies to apply the patch by 30 July 2026.
What to do: If you manage an on-premises VCO instance, patch to the fixed release immediately. If patching is not immediately possible, restrict web interface access to trusted administrative networks only and check your logs against those three attacker IP addresses.
Sources

