ZeroHour

CVE-2026-16812

KEVmoderate

OS Command Injection in Arista VeloCloud Orchestrator On-Prem

CISA: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

CVSS 4.0
10.0 critical
EPSS
2%p74
Published
()
KEV added
AI analysis

Arista VeloCloud Orchestrator (VCO) On-Prem, the centralized management platform for VeloCloud SD-WAN networks, contains an OS command injection vulnerability (CWE-78) that allows a remote attacker to execute operating system commands, reach privileged internal functionality, and impact the underlying VCO host. The available advisory text does not describe the exact injection point or authentication requirements, but the flaw is exploitable remotely against the on-premises orchestrator. A successful attack can compromise the confidentiality, integrity, and availability of the orchestrator and of the configuration and network data it manages. Organizations running an on-premises VeloCloud Orchestrator are affected; CISA scopes the flaw to the on-prem product, provides no version ranges in this data, and no CVSS score has been published yet. The flaw was added to CISA's KEV on 2026-07-27, confirming exploitation in the wild, while ransomware use is unknown, no public proof-of-concept is available, and EPSS currently puts 30-day exploitation probability at 1.6% (74th percentile).

What to do: Follow Arista's VeloCloud security advisory: match your on-prem VCO release against the advisory's affected list and apply the fixed update as soon as possible, as required for U.S. federal agencies under BOD 26-04 by the CISA deadline. Until patched, restrict the orchestrator's web/API access to trusted management networks or VPN, verify whether your VCO is internet-exposed, and hunt for signs of unexpected command execution or privileged activity on the VCO host per CISA's forensics triage requirements; if mitigations are unavailable, follow BOD 26-04 guidance on discontinuing use of the product.

Affected
Arista VeloCloud Orchestrator On-Prem
Estimated exposure
moderate≈1,000–10,000 on-prem orchestrator deployments (the vulnerable management servers), with downstream managed SD-WAN edge fleets far larger — No published install counts were available, so this is a deployment-pattern estimate: the VeloCloud Orchestrator is a per-organization (or multi-tenant MSP) management server and most VeloCloud tenants historically use vendor-hosted cloud…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited.

CISA Known Exploited Vulnerability
Affected
Arista VeloCloud Orchestrator
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Due date
Ransomware use
Unknown
Vendors
arista
Products
velocloud orchestrator
Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X

In the news