<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/arista-patches-critical-velocloud-orchestrator-command-injection-flaw-under-active-exploitation-2rfhbdthl" -->

---
title: Arista patches critical VeloCloud Orchestrator command...
description: Arista Networks has patched CVE-2026-16812, a CVSS 10.0 unauthenticated OS command injection vulnerability in its on-premises VeloCloud Orchestrator (VCO) web...
canonical: https://daily.dev/posts/arista-patches-critical-velocloud-orchestrator-command-injection-flaw-under-active-exploitation-2rfhbdthl
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Arista patches critical VeloCloud Orchestrator command injection flaw under active exploitation | daily.dev
og:description: Arista Networks has patched CVE-2026-16812, a CVSS 10.0 unauthenticated OS command injection vulnerability in its on-premises VeloCloud Orchestrator (VCO) web...
og:url: https://daily.dev/posts/arista-patches-critical-velocloud-orchestrator-command-injection-flaw-under-active-exploitation-2rfhbdthl
og:image: https://api.daily.dev/og/posts/2RFHBdThL.png
og:image:alt: Arista patches critical VeloCloud Orchestrator command injection flaw under active exploitation
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Arista patches critical VeloCloud Orchestrator command injection flaw under active exploitation

**[Collections](https://daily.dev/sources/collections)** · 1 min read · 0 upvotes · 0 comments

## Summary

Arista Networks has patched CVE-2026-16812, a CVSS 10.0 unauthenticated OS command injection vulnerability in its on-premises VeloCloud Orchestrator (VCO) web interface. No credentials are needed to exploit it, and successful exploitation can compromise the orchestrator and all SD-WAN edge devices it manages. Affected versions are VCO 5.2.x, 6.1.x, 6.4.x, and 7.0.x. The flaw is already being actively exploited in the wild. CISA has added it to its Known Exploited Vulnerabilities catalog, requiring federal agencies to remediate by July 30, 2026. Arista has published three attacker IP addresses as indicators of compromise and recommends restricting interface access, rotating credentials, and reviewing logs.

## Content

Arista Networks has patched a maximum-severity vulnerability in its on-premises VeloCloud Orchestrator (VCO) that attackers are already exploiting in the wild.

The flaw, tracked as CVE-2026-16812, scores a perfect 10.0 on the CVSS scale. It's an unauthenticated OS command injection bug in the VCO web interface, meaning an attacker needs nothing more than network access to the interface to run privileged commands on the underlying system. No credentials required. If exploited successfully, an attacker could compromise not just the orchestrator itself but all the SD-WAN edge devices it manages.

Affected versions include VCO 5.2.x, 6.1.x, 6.4.x, and 7.0.x. Patches are available now.

CISA has added the CVE to its Known Exploited Vulnerabilities catalog and is requiring federal agencies to remediate by July 30, 2026.

Arista has published three attacker IP addresses as indicators of compromise. The company recommends restricting access to the VCO web interface, rotating credentials, and reviewing logs for signs of exploitation if you haven't patched yet.

## Similar posts on daily.dev

- [VMware fixes command injection flaw in Aria Operations](https://daily.dev/posts/vmware-fixes-command-injection-flaw-in-aria-operations-ue2mrjloo) · CSO Online · 0 upvotes · 0 comments
- [VMware Aria Operations Bug Exploited, Cloud Resources at Risk](https://daily.dev/posts/vmware-aria-operations-bug-exploited-cloud-resources-at-risk-6wzhmakwc) · Dark Reading · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#networking](https://daily.dev/tags/networking)

[View this post on daily.dev](https://daily.dev/posts/arista-patches-critical-velocloud-orchestrator-command-injection-flaw-under-active-exploitation-2rfhbdthl)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Arista patches critical VeloCloud Orchestrator command injection flaw under active exploitation","url":"https://daily.dev/posts/arista-patches-critical-velocloud-orchestrator-command-injection-flaw-under-active-exploitation-2rfhbdthl","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/arista-patches-critical-velocloud-orchestrator-command-injection-flaw-under-active-exploitation-2rfhbdthl"},"datePublished":"2026-07-28T09:18:49.117Z","dateModified":"2026-07-28T09:19:28.271Z","description":"Arista Networks has patched CVE-2026-16812, a CVSS 10.0 unauthenticated OS command injection vulnerability in its on-premises VeloCloud Orchestrator (VCO) web...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/514a9daa658dd13fac7b5c33c89114db?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/514a9daa658dd13fac7b5c33c89114db?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/arista-patches-critical-velocloud-orchestrator-command-injection-flaw-under-active-exploitation-2rfhbdthl","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,networking","timeRequired":"PT1M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Arista patches critical VeloCloud Orchestrator command injection flaw under active exploitation"}]}
```

