ADVISORY SUMMARY
CVE-2026-16812 is a CVSS 10.0 unauthenticated OS command injection flaw in Arista VeloCloud Orchestrator On-Prem that allows remote attackers to access privileged internal functionality and execute arbitrary OS commands on the VCO host. Arista confirmed active exploitation and stated the on-premises orchestrator is exposed by default with no configuration capable of removing that exposure entirely. CISA added it to the KEV on July 27, 2026, with a federal remediation deadline of July 30, 2026 under BOD 26-04.
AFFECTED SYSTEMS
MITIGATION GUIDANCE
Upgrade VeloCloud Orchestrator On-Prem to fixed versions: 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1. Hosted and Dedicated VCO offerings were already patched prior to disclosure. Immediately isolate VCO management interfaces from direct internet exposure. No configuration-based workaround exists; patching is the only remediation.
DETECTION SIGNATURES
Scan for anomalous HTTP POST/GET requests to VCO internal API endpoints from external IPs. Monitor OS command execution logs on the VCO host for unexpected shell activity. Alert on new user creation or privilege escalation events on the orchestrator. Review network logs for scanning activity targeting the VCO web interface on TCP/443.
REFERENCES
- → https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
- → https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
- → https://nvd.nist.gov/vuln/detail/CVE-2026-16812