The record
Written from the 2 reports below. Nothing here is unsourced.
- Arista disclosed and patched CVE-2026-16812, a maximum-severity (CVSS 10.0) command injection vulnerability in its on-premises VeloCloud Orchestrator (VCO) platform that is already being actively exploited in the wild.
- The flaw allows a remote, unauthenticated attacker to execute commands on the underlying host and access privileged internal functionality, potentially compromising the entire SD-WAN orchestration layer.
- Affected versions span VCO 5.2.x through 7.0.x; Arista has released fixed builds for each branch and listed the bug on CISA's Known Exploited Vulnerabilities catalog.
- Because VCO controls enterprise branch connectivity, successful exploitation could give attackers a pivot point across an organization's entire wide-area network topology.
- Coverage from BleepingComputer and the NVD is consistent—there is no competing narrative, only urgency around patching.
- Organizations must upgrade immediately and, as an interim measure, restrict VCO web access to administrative networks and review administrator logs for signs of abuse.
What to watch next
- Upgrade VCO to 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1+
- Restrict VCO web UI access to administrative networks only
- Review VCO admin logs for unusual changes or unknown IPs
What changed2
Every report on this story, newest first. Times are when each outlet published.
The Hacker News[1]
Attackers Exploit Arista VeloCloud Orchestrator Command Injection FlawBleepingComputer[2]
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Why it matters3
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Arista VeloCloud Orchestrator on-prem deployments remote privileged access· immediate
- Enterprises using VCO 5.2.x–7.0.x patch required· days
- VCO administrators operational disruption· days
Coverage2
All filed from United StatesSingle origin
Named Alibaba · Arista · Arista VeloCloud Orchestrator · CISA · Fastjson · Federal Civilian Executive Branch · Fortinet · FortiOS SSL-VPN · VeloCloud Orchestrator · VeloCloud SD-WAN
The 2 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.

