TL;DR: Arista confirmed that CVE-2026-16812, a VeloCloud command injection flaw, is under active attack. The bug scores a maximum CVSS 10.0 and needs no credentials. Arista also patched two related VeloCloud Orchestrator bugs, though neither is exploited.
Why This VeloCloud Command Injection Matters
VeloCloud Orchestrator (VCO) manages SD-WAN networks at scale. CVE-2026-16812 lets a remote attacker run OS commands on the VCO host. It needs no login, and the exposed functionality is reachable by default.
Arista states the risk plainly in Security Advisory 0144. The flaw is a CWE-78 OS command injection with a perfect 10.0 score. A compromise can also expose managed VeloCloud Edge devices.
How the Attack Works
The vulnerable feature was meant for internal use only. However, it stayed reachable over the network. An attacker sends crafted input that reaches an OS command, then runs code as the orchestrator.
Arista listed three attacker IP addresses in the advisory: 8.19.75.217, 206.72.242.124, and 206.72.242.162. It also warned that no single indicator of compromise exists, so operators should review web and backend logs closely.
Two More VeloCloud Orchestrator Bugs
Security Advisory 0145 covers two lower-severity issues. CVE-2026-17191 is a SQL injection that enables SSRF, scored CVSS 9.1. CVE-2026-17192 is a separate SSRF flaw, scored CVSS 8.5. Both need an authenticated session, and Arista found no malicious use of either.
Affected Versions
The exploited flaw hits VCO on-prem across these trains:
- VCO 5.2.x before 5.2.3.14
- VCO 6.1.x before 6.1.3.4
- VCO 6.4.x before 6.4.2.4
- VCO 7.0.x before 7.0.0.1
Arista already patched its Hosted and Dedicated VCO instances.
Patch and Mitigation Steps
Upgrade on-prem VCO to a fixed release now: 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1. Because CVE-2026-16812 is exploited in the wild, treat this as urgent. Meanwhile, restrict the VCO web interface to trusted networks and block the published attacker IPs. Then review logs for unexpected outbound connections and command execution.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.