VMTech
+381 11 4183 54024/7 Discuss a project
← All Instagram insights VMTECH · INSTAGRAM · Security

Arista VeloCloud Orchestrator CVSS 10.0 flaw is being exploited

Arista VeloCloud Orchestrator CVSS 10.0 flaw is being exploited

On July 28, 2026, Arista confirmed active exploitation of CVE-2026-16812, a CVSS 10.0 operating system command injection flaw in on-premises VeloCloud Orchestrator. A remote attacker may access privileged internal functions and execute arbitrary code on the VCO host.

Why the vulnerability is critical

VCO manages network infrastructure and sensitive orchestration data. A successful attack can undermine its confidentiality, integrity and availability, while giving the intruder a potential route to managed VeloCloud Edge devices.

The risk is limited to on-premises deployments. Arista had already remediated the issue in hosted and dedicated VCO environments.

Affected releases and attack indicators

The vulnerable branches and first fixed releases are:

  • VCO 5.2.x before 5.2.3.14
  • VCO 6.1.x before 6.1.3.4
  • VCO 6.4.x before 6.4.2.4
  • VCO 7.0.x before 7.0.0.1
Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Arista said the flaw was discovered externally but did not disclose the scale of the attacks. It identified three attacking IP addresses: 8.19.75.217, 206.72.242.124 and 206.72.242.162.

Required response

Operators should update immediately. Where that is not possible, they should restrict the VCO web interface to trusted administrative networks, monitor for the listed IPs and unexpected outbound traffic, and review administrator activity. Before remediation, suspected victims should preserve web, application, system and database logs, along with relevant file-system timestamps.

CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and set July 30, 2026, as the remediation deadline for US federal civilian agencies.

CISA also listed FortiOS SSL-VPN flaw CVE-2025-68686, patched in February, with an August 10 deadline. Separately, actively exploited Fastjson flaw CVE-2026-16723 affects versions 1.2.68 through 1.2.83 and remains unpatched; developers should enable SafeMode or migrate to an unaffected build.

For businesses running VCO on-premises, patching alone may be insufficient after suspected compromise. Teams should validate Edge device state, rotate credentials, audit administrator actions and, where necessary, restore or replace the orchestrator from a trusted source.

#arista#velocloud#vulnerability#cybersecurity
Current metrics
0Views
0Reach
0Likes
0Comments
0Saved
0Shares
Instagram

Arista VeloCloud Orchestrator CVSS 10.0 flaw is being exploited

Open the post on Instagram ↗