CVE-2026-16812 is a critical CVSS 10.0 vulnerability in Arista VeloCloud Orchestrator being actively exploited. Patch on-premise systems immediately.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| velocloud_orchestrator | 5.2.0 | 5.2.3.14 | vulnerable |
| velocloud_orchestrator | 6.1.0 | 6.1.3.4 | vulnerable |
| velocloud_orchestrator | 6.4.0 | 6.4.2.4 | vulnerable |
| velocloud_orchestrator | 7.0.0 | 7.0.0 | vulnerable |
Arista has released urgent security updates to address this flaw. Administrators using on-premise VeloCloud Orchestrator must consult Arista Security Advisory 0144 and apply the recommended patches immediately.
Ensure your VCO deployment is updated to version 5.2.3.14, 6.1.3.4, 6.4.2.4, or a later release. Systems running version 7.0.0 or earlier within these branches are confirmed vulnerable and require an immediate upgrade.
Since the vulnerability involves exposure of internal-only functionality, ensure the VCO management interface is not reachable from the public internet. Implement strict firewall rules and use a VPN to restrict access to trusted administrative IP ranges.
Perform a forensic audit of your orchestrator logs. Look for evidence of unauthorized access to internal APIs or unusual system-level commands, following CISA’s Forensics Triage Requirements to identify potential indicators of compromise.
"Detection should focus on identifying unauthorized access to internal-only API endpoints and monitoring for OS command injection attempts. Review web server and application logs for unusual HTTP requests or administrative actions originating from external or unknown IP addresses. Organizations should also deploy network signatures to detect exploitation attempts against the VeloCloud Orchestrator management interface and perform historical log analysis to identify potential breaches that occurred before patching."
Experience superior visibility and a simpler approach to cyber risk management