Back to Home
Security

Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock

Unauthenticated command injection scores perfect 10 and may expose managed Edge devices

t
tech4you AI
July 28, 20262 min read
Share

security

Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock

Unauthenticated command injection scores perfect 10 and may expose managed Edge devices

A critical flaw in Arista's VeloCloud Orchestrator has gone from zero to KEV in short order, with the networking giant confirming attackers are already exploiting it.

The vulnerability, tracked as CVE-2026-16812, carries a maximum CVSS score of 10.0 and affects VeloCloud Orchestrator On-Prem, the self-hosted version of the software that enterprises use to centrally manage VeloCloud software-defined wide area networks (SD-WANs) connecting branch offices, datacenters, and clouds environments.

According to Arista's security advisory, the flaw is an OS command injection vulnerability that allows an unauthenticated remote attacker to reach privileged internal functionality that was never meant to be exposed externally. 

Worse, Arista says the on-premises orchestrator is exposed by default, with no configuration capable of removing that exposure entirely. Exploitation requires access to the web interface but no credentials. Until administrators can patch, Arista recommends restricting that interface to trusted management networks and blocking IP addresses associated with observed attacks.

"Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator," Arista warned. "Compromises to the VCO platform may allow attackers access to the VeloCloud Edge devices as well."

Arista published three IP addresses observed conducting attacks, but otherwise kept its cards close to its chest. The company hasn't said who's exploiting the bug, when the attacks began, or how many customers have been affected, and didn't immediately respond to The Register's questions.

Even without those details, the admission of in-the-wild exploitation was enough for CISA to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog. The list is reserved for bugs with evidence of real-world abuse, and while the associated directive applies only to US federal civilian agencies, plenty of private sector security teams use KEV to decide which patches can't wait.

The issue affects only on-premises deployments. Customers using Arista's hosted or dedicated VeloCloud Orchestrator service had already been patched before the advisory was published, the company said.

Fixes are available in VeloCloud Orchestrator versions 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. Arista urged customers running earlier releases to upgrade immediately.

Arista is far from the first vendor to issue a patch after attackers had already begun exploiting the flaw. Over the past year, a steady stream of networking gear, VPNs, firewalls, and other edge-facing enterprise software has followed the same pattern: by the time customers learn there's a problem, somebody else has already proved it's worth exploiting. ®


Originally published on The Register

Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock | tech4you