All stories

Unauthenticated attackers exploit critical command injection vulnerability in Arista VeloCloud Orchestrator

Arista has released patches for a critical OS command injection vulnerability in the on-premises VeloCloud Orchestrator (VCO) that is currently being exploited in the wild. The flaw allows remote attackers to access privileged internal functions without any authentication or special configuration. If you run VCO On-Prem, upgrade your software immediately and restrict web interface access to trusted networks.

Summary

Arista Networks has addressed a maximum-severity security defect in its VeloCloud Orchestrator (VCO) On-Prem management platform. The vulnerability, tracked as CVE-2026-16812, enables remote attackers to execute commands and access privileged functionality intended strictly for internal use.

The flaw is being actively exploited by external actors. Because the VCO web interface is exposed by default and requires no credentials for exploitation, any attacker with network access to the interface can target these systems. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies remediate the issue within three days.

Technical details

The defect is an OS command injection vulnerability (CWE-78). It allows a remote attacker to bypass standard access controls to reach internal functions that should not be reachable via the web interface.

Successful exploitation can compromise the confidentiality, integrity, and availability of the orchestrator host and all data it manages. This includes sensitive configuration data, device inventories, credentials, certificates, and cryptographic key material. Furthermore, a compromise of the VCO platform may grant attackers access to connected VeloCloud Edge devices.

Affected products and fixed versions

The vulnerability specifically impacts VeloCloud Orchestrator On-Prem (formerly known as VeloCloud Orchestrator by Broadcom). Hosted and Dedicated versions were patched prior to the advisory and are not affected. VeloCloud Gateway and VeloCloud Edge products are also not vulnerable.

To remediate the flaw, operators must upgrade to one of the following fixed releases:

Release Train Fixed Version
VCO 5.2.x 5.2.3.14 or later
VCO 6.1.x 6.1.3.4 or later
VCO 6.4.x 6.4.2.4 or later
VCO 7.0.x 7.0.0.1 or later

Arista notes that end-of-support software versions have not been assessed for this vulnerability. Customers on unsupported release trains should contact the Arista Technical Assistance Center (TAC) to discuss upgrade paths.

Detection opportunities

There is no single definitive indicator of compromise for this issue, but defenders should hunt for specific patterns in VCO logs.

Web Access Logs Search for requests containing:

  • Unusual URL-like path components
  • Encoded characters
  • References to local or internal services
  • Abnormally high request rates

System and Application Logs Review backend application and system logs for:

  • Unexpected outbound HTTP or HTTPS activity originating from the VCO host
  • Privileged maintenance actions not associated with known administrative workflows
  • Unexpected command execution, file creation, or database exports
  • Access to sensitive files such as device inventories, credentials, or certificates

If a compromise is suspected, Arista advises preserving VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before beginning remediation.

Defender guidance

Immediate action is required due to the active exploitation of this zero-day.

  1. Patching: Upgrade to the fixed versions listed above as soon as possible.
  2. Network Isolation: Restrict access to the VCO web interface so it is only reachable from trusted administrative networks. This reduces the attack surface since the interface is exposed by default.
  3. IP Blocking: Arista identified three IP addresses seen exploiting this vulnerability. While these may not represent all attackers, they should be blocked:
    • 185.244.214.10
    • 193.233.236.173
    • 212.192.231.10
  4. Post-Compromise Recovery: If you find evidence of a breach, patching alone may not be sufficient. Operators should consider rotating credentials, validating the state of managed devices, and restoring or replacing affected orchestrator instances from trusted sources.

Sources

  1. https://www.securityweek.com/critical-arista-velocloud-orchestrator-vulnerability-exploited-as-zero-day/
  2. https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/
  3. https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
  4. https://event.on24.com/wcc/r/ 5410205/7BF2B1A3329F74BE93B2AE247EDCDE5B?partnerref=awidget
  5. https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -