ADVISORY SUMMARY
A maximum-severity (CVSS 10.0) unauthenticated OS command injection flaw in Arista VeloCloud Orchestrator On-Prem allows remote attackers to reach privileged internal functionality, execute arbitrary commands, and fully compromise the orchestrator host and all managed SD-WAN edge devices. Active exploitation was confirmed by Arista and CISA added it to the KEV catalog on July 27, 2026 with a federal FCEB remediation deadline of July 30. Hosted and dedicated VCO versions were patched ahead of the disclosure; only on-premises deployments require customer action.
AFFECTED SYSTEMS
MITIGATION GUIDANCE
Apply the vendor-supplied VCO On-Prem patch immediately per Arista's security advisory. After patching, perform credential rotation for all administrator accounts on the orchestrator. Validate the state of all managed VeloCloud Edge devices and restore or replace affected orchestrator instances from trusted backups if compromise is suspected. Restrict VCO management interface exposure to the internet; place behind VPN or network access control where operationally feasible.
DETECTION SIGNATURES
Scan for internet-exposed VCO management endpoints (default ports). Review VCO HTTP access logs for anomalous POST/GET requests to privileged internal API paths. Investigate any unexpected command execution events or new scheduled jobs on the orchestrator host. Audit administrator activity logs within VCO for unauthorized configuration changes to managed edge devices.
REFERENCES
- → https://www.arista.com/en/support/advisories-notices/security-advisories/
- → https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- → https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html
- → https://nvd.nist.gov/vuln/detail/CVE-2026-16812