By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Arista VeloCloud Orchestrator Vulnerability Actively Exploited

A critical security vulnerability affecting on-premises versions of Arista VeloCloud Orchestrator (VCO) is currently being actively exploited by malicious actors. This flaw, identified as CVE-2026-16812, has been assigned a maximum CVSS score of 10.0, indicating its severe impact. The vulnerability is classified as an operating system command injection, which permits attackers to execute arbitrary code on the affected systems. This capability can lead to a complete compromise of the targeted infrastructure, allowing attackers to gain unauthorized control, steal sensitive data, or deploy further malicious software.
The Arista VeloCloud Orchestrator is a key component for managing and orchestrating Software-Defined Wide Area Networks (SD-WAN) deployed by enterprises. SD-WAN solutions are designed to improve network performance, reduce costs, and enhance agility by intelligently routing traffic across various network connections. The on-premises deployment model means that the VCO software is installed and managed directly within an organization's own data centers or network infrastructure, rather than being hosted by a cloud provider. This makes the security of the on-premises VCO particularly crucial for organizations relying on it for their network operations.
While the specific details of how attackers are exploiting this vulnerability in the wild have not been fully disclosed, the nature of command injection flaws typically involves tricking the vulnerable application into executing commands that were not intended by the developers. This can be achieved through specially crafted input fields or network requests that bypass normal security checks. The successful exploitation of CVE-2026-16812 could allow an unauthenticated attacker to gain privileged access to the VCO appliance, potentially leading to the disruption of network services, data exfiltration, or the use of the compromised orchestrator to launch further attacks against other network devices or endpoints.
Arista Networks, the provider of VeloCloud technology, has acknowledged the vulnerability and is expected to release security advisories and patches to address the issue. Organizations utilizing on-premises Arista VeloCloud Orchestrator deployments are strongly advised to monitor for official communications from Arista and to apply any available security updates as soon as possible. Proactive security measures, such as network segmentation and intrusion detection systems, can also help mitigate the risk of exploitation and limit the potential damage if an attack occurs. The active exploitation of this high-severity flaw underscores the persistent threat landscape and the importance of timely vulnerability management for critical network infrastructure.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.