Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-16812

Published 2026-07-27
Updated 2 months ago
Vendor/s
Arista
Product/s
VeloCloud Orchestrator
Version/s
5.2.0 > 5.2.3.14
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
10
/ 10
Critical
Severity Details
Base score
10 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-16812 is a critical CVSS 10.0 vulnerability in Arista VeloCloud Orchestrator being actively exploited. Patch on-premise systems immediately.

CPE

Arista logo
Arista
Product Version Start Version End (excl.) Status
velocloud_orchestrator 5.2.0 5.2.3.14 vulnerable
velocloud_orchestrator 6.1.0 6.1.3.4 vulnerable
velocloud_orchestrator 6.4.0 6.4.2.4 vulnerable
velocloud_orchestrator 7.0.0 7.0.0 vulnerable

Related weakness (CWE)

CWE-78

Remediation plan

1

Apply official patches

Arista has released urgent security updates to address this flaw. Administrators using on-premise VeloCloud Orchestrator must consult Arista Security Advisory 0144 and apply the recommended patches immediately.

2

Update affected systems

Ensure your VCO deployment is updated to version 5.2.3.14, 6.1.3.4, 6.4.2.4, or a later release. Systems running version 7.0.0 or earlier within these branches are confirmed vulnerable and require an immediate upgrade.

3

Restrict access

Since the vulnerability involves exposure of internal-only functionality, ensure the VCO management interface is not reachable from the public internet. Implement strict firewall rules and use a VPN to restrict access to trusted administrative IP ranges.

4

Monitor for exploitation

Perform a forensic audit of your orchestrator logs. Look for evidence of unauthorized access to internal APIs or unusual system-level commands, following CISA’s Forensics Triage Requirements to identify potential indicators of compromise.

Detection Guidance

"Detection should focus on identifying unauthorized access to internal-only API endpoints and monitoring for OS command injection attempts. Review web server and application logs for unusual HTTP requests or administrative actions originating from external or unknown IP addresses. Organizations should also deploy network signatures to detect exploitation attempts against the VeloCloud Orchestrator management interface and perform historical log analysis to identify potential breaches that occurred before patching."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management