A highly critical OS command injection vulnerability, 'CVE-2026-16812' (CVSS score 10.0), has been discovered in Arista Networks VeloCloud Orchestrator (VCO) On-Prem, with active exploitation confirmed. This vulnerability allows an unauthenticated remote attacker to execute arbitrary OS commands with elevated privileges on the VCO host, jeopardizing confidentiality, integrity, and availability. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its 'Known Exploited Vulnerabilities (KEV) Catalog' and mandates that U.S. federal agencies complete remediation by July 30, 2026.
Immediate Actions to Take
- ✓Update to the patched version available in official advisories
- ✓Apply official workarounds until the update is complete
- ✓Check for signs of compromise
Vulnerability Overview and Scope of Impact
This vulnerability affects Arista VeloCloud Orchestrator (VCO) On-Prem environments. A privileged function, originally intended for internal use, is remotely accessible. Exploiting this flaw allows an unauthenticated attacker to perform OS command injection on the VCO host. As a result, attackers can completely compromise the confidentiality, integrity, and availability of VCO and the data it manages. While Hosted and Dedicated versions of VCO were patched before this issue was made public, organizations using the On-Prem version require immediate action.
Specific Impacts and Attack Scenarios
Attackers can exploit this vulnerability without authentication, requiring only network access to the VCO web interface. This allows them to remotely execute arbitrary OS commands on the VCO host and gain complete control of the system. Attacks exploiting this vulnerability have already been confirmed, and CISA has published three related malicious IP addresses (8.19.75.217, 206.72.242.124, 206.72.242.162), recommending monitoring and blocking them. As VCO is central to SD-WAN management and operations, its compromise could lead to catastrophic consequences such as loss of control over the entire network, access to confidential information, configuration changes, and service disruptions.
Remediation Steps and Verification Methods
Arista Networks has released patches to address this vulnerability. Users of VCO On-Prem should immediately consult the vendor's security advisory and update to the latest patched version appropriate for their deployed version. If updating is not immediately feasible, it is recommended to restrict network access to the VCO web interface, minimizing external exposure. Additionally, thoroughly review system logs for any connection history from the published malicious IP addresses to detect early signs of compromise.
📦