VULNERABILITY OVERVIEW
An unauthenticated OS command injection vulnerability (CWE-78) in the VeloCloud Orchestrator On-Prem web interface allows remote attackers to access privileged internal functionality never intended for external exposure, enabling full compromise of the orchestrator and all managed SD-WAN edge devices. Arista confirmed the vulnerability was externally discovered and is known to be actively exploited in the wild. Added to CISA KEV on July 27, 2026; Hosted and Dedicated VCO deployments were pre-patched before public disclosure.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONS
VCO On-Prem 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.2.4, 7.0.x prior to 7.0.0.1CITATIONS
- → https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
- → https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/
- → https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
- → https://www.securityweek.com/critical-arista-velocloud-orchestrator-vulnerability-exploited-as-zero-day/