Intelligence
criticalVulnerabilityActive

Active exploitation of Arista VeloCloud Orchestrator RCE; on-premises deployments at immediate risk

CVE-2026-16812, a maximum-severity command injection flaw in Arista VeloCloud Orchestrator on-premises versions, is being actively exploited in the wild to achieve remote code execution. Organisations running on-premises VCO instances require immediate patching.

S
Sebastion

CVE References

Affected

Arista VeloCloud Orchestrator (on-premises)

Arista VeloCloud Orchestrator on-premises deployments face active exploitation of CVE-2026-16812, a command injection vulnerability rated CVSS 10.0. The flaw permits unauthenticated or low-privilege attackers to inject operating system commands through the orchestrator's input handling, leading to arbitrary code execution with the privileges of the VCO process. Given VCO's role as a centralised management platform for SD-WAN deployments, compromise grants attackers control over network traffic routing, segmentation policies, and connectivity across potentially hundreds of branch locations.

The vulnerability's severity stems from several factors: VCO instances typically operate in trust-critical network positions, often accessible from branch locations or with limited network segmentation in practice. Successful exploitation enables attackers to modify traffic policies, intercept communications, redirect network flows to attacker-controlled infrastructure, or maintain persistent access across the managed WAN. The active exploitation status indicates reconnaissance and initial compromise attempts are occurring, suggesting the vulnerability details are sufficiently public or have been reverse-engineered by threat actors.

Organisations running on-premises VCO instances should treat this as a business-critical remediation priority. Immediate actions include: isolating VCO management interfaces behind additional authentication layers or network controls, applying Arista's security patches as they become available, reviewing access logs and network flow changes for signs of compromise, and considering temporary failover to cloud-hosted VCO instances if available. The on-premises deployment model, chosen for operational control or regulatory reasons, now represents a concentrated target that lacks Arista's ability to push rapid patches at scale.

This incident reflects a broader pattern of SD-WAN orchestrators becoming high-value targets. These platforms provide a single pane of control over distributed network infrastructure, making them particularly attractive for supply-chain or lateral movement attacks. The shift toward exploiting on-premises infrastructure components suggests threat actors are recognising that organisations may over-invest in cloud security whilst maintaining legacy on-premises management systems with weaker access controls or update cadences. Defenders should audit their entire SD-WAN deployment architecture for similar orchestrator-layer vulnerabilities and enforce strict change control and audit logging on management infrastructure.