Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-68686 | Unauthenticated Info-Exposure Bypass of Symlink Patch in Fortinet FortiOS CVE-2025-68686 is a sensitive-information-exposure flaw (CWE-200) in Fortinet FortiOS that allows a remote, unauthenticated attacker to bypass the vendor's patch for the symbolic-link (symlink) persistency mechanism seen in some post-exploitation cases. It is triggered by crafted HTTP requests sent to a device that has already been compromised through another vulnerability at the filesystem level, for example where symlinks were planted to maintain access to files. By bypassing the patch, the attacker can keep retrieving sensitive information from an otherwise remediated FortiGate device. Any organization running an affected FortiOS release is potentially affected; the CISA data does not enumerate specific versions, so administrators should consult Fortinet's advisory for the affected branches. The flaw was added to CISA's KEV catalog on 2026-07-27, confirming real-world exploitation, and EPSS assigns a 29.6% probability of exploitation within 30 days (98th percentile), with ransomware use currently unknown. Do: Patch affected FortiOS devices per Fortinet's current advisory, following BOD 26-04 timelines for federal agencies (apply mitigations per vendor instructions or discontinue use where mitigations are unavailable). Because this flaw defeats the earlier symlink-persistence fix, re-check previously remediated devices for residual or recreated symlinks and hunt for indicators of prior filesystem-level compromise, such as unexpected symlinks and anomalous SSL-VPN activity. Review logs for crafted HTTP requests and prioritize internet-facing FortiGate assets for patching and triage. | 5.9 | 30% | KEV |
| mass~300,000+ internet-exposed FortiGate/FortiOS devices | |
| CVE-2026-16723 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required. NVD description · AI analysis pending | 9.0 | 16% | — | — | ||
| CVE-2026-16812 | OS Command Injection in Arista VeloCloud Orchestrator On-Prem Arista VeloCloud Orchestrator (VCO) On-Prem, the centralized management platform for VeloCloud SD-WAN networks, contains an OS command injection vulnerability (CWE-78) that allows a remote attacker to execute operating system commands, reach privileged internal functionality, and impact the underlying VCO host. The available advisory text does not describe the exact injection point or authentication requirements, but the flaw is exploitable remotely against the on-premises orchestrator. A successful attack can compromise the confidentiality, integrity, and availability of the orchestrator and of the configuration and network data it manages. Organizations running an on-premises VeloCloud Orchestrator are affected; CISA scopes the flaw to the on-prem product, provides no version ranges in this data, and no CVSS score has been published yet. The flaw was added to CISA's KEV on 2026-07-27, confirming exploitation in the wild, while ransomware use is unknown, no public proof-of-concept is available, and EPSS currently puts 30-day exploitation probability at 1.6% (74th percentile). Do: Follow Arista's VeloCloud security advisory: match your on-prem VCO release against the advisory's affected list and apply the fixed update as soon as possible, as required for U.S. federal agencies under BOD 26-04 by the CISA deadline. Until patched, restrict the orchestrator's web/API access to trusted management networks or VPN, verify whether your VCO is internet-exposed, and hunt for signs of unexpected command execution or privileged activity on the VCO host per CISA's forensics triage requirements; if mitigations are unavailable, follow BOD 26-04 guidance on discontinuing use of the product. | 10.0 | 2% | KEV |
| moderate≈1,000–10,000 on-prem orchestrator deployments (the vulnerable management servers), with downstream managed SD-WAN edge fleets far larger |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 206.72.242.124 | iew the logs to determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 "If compromise is suspected, operators shoul |
| ipv4 | 206.72.242.162 | determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 "If compromise is suspected, operators should preserve VCO |
| ipv4 | 5.2.3.14 | llowing versions are affected - VCO 5.2.x releases prior to 5.2.3.14 VCO 6.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prio |
| ipv4 | 6.1.3.4 | .2.x releases prior to 5.2.3.14 VCO 6.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prio |
| ipv4 | 6.4.2.4 | 6.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prior to 7.0.0.1 Arista acknowledged tha |
| ipv4 | 7.0.0.1 | 6.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prior to 7.0.0.1 Arista acknowledged that the vulnerability was externally d |
| ipv4 | 8.19.75.217 | them and review the logs to determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 "If compromise is suspected, |
Full article644 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJul 28, 2026Vulnerability / Threat Intelligence
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution.
"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host," Arista said in a Monday advisory.
"Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible."
The American network equipment company said the issue has already been addressed in hosted and dedicated versions of VCO in advance. The following versions are affected -
- VCO 5.2.x releases prior to 5.2.3.14
- VCO 6.1.x releases prior to 6.1.3.4
- VCO 6.4.x releases prior to 6.4.2.4
- VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
As indicators of compromise (IoCs), the company shared a set of three IP addresses that it said were responsible for "conducting the attacks," urging customers to block them and review the logs to determine if they are present -
- 8.19.75.217
- 206.72.242.124
- 206.72.242.162
"If compromise is suspected, operators should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible," it added.
If immediate updating to a fixed VCO release is not an option, it's recommended to restrict access to the VCO web interface to trusted administrative networks, monitor the VCO for access from known malicious source IPs, check for unexpected outbound network activity from the VCO host, and review recent administrator activity for unexpected changes.
"Compromises to the VCO platform may allow attackers access to the VeloCloud Edge devices as well," Arista said. "This may include credential rotation, review of administrator activity, validation of managed device state, and restoration or replacement of affected orchestrator instances from trusted sources."
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patch by July 30, 2026.
News of active exploitation of CVE-2026-16812 arrives as the agency also added a medium-severity security vulnerability impacting Fortinet FortiOS SSL-VPN (CVE-2025-68686, CVSS score: 5.3) to the KEV catalog, citing evidence of active exploitation. The shortcoming was patched by Fortinet earlier this February.
"An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiOS SSL-VPN may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests," Fortinet said in an alert at the time. "An attacker would need first to have compromised the product via another vulnerability, at the file system level."
There are currently no details on how the vulnerability is being exploited in the wild, the scale of attacks, and who is behind them. Federal agencies have time till August 10, 2026, to apply the patches.
Another security flaw that has come under attack is CVE-2026-16723 (CVSS score: 9.0), a critical issue in Alibaba's Fastjson library that could allow remote code execution without user interaction or elevated privileges. The vulnerability remains unpatched. Developers using versions 1.2.68 through 1.2.83 are urged to enable SafeMode or switch to a non-impacted build as soon as possible.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html