Alastor InfoSec
← Back to Blog
Vulnerability

July 30, 2026 · Alastor InfoSec Team

CVE-2026-16812: Arista VeloCloud Orchestrator CVSS 10.0 Zero-Day Exploited — Federal Patch Deadline Today

CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities (KEV) catalog on July 27, 2026, with a federal patch deadline of July 30 — today. The vulnerability is a CVSS 10.0 OS command injection flaw in Arista VeloCloud Orchestrator On-Prem, the self-hosted platform enterprises use to centrally manage their SD-WAN deployments. Active exploitation was confirmed prior to the CISA addition, meaning attackers were already inside networks before most administrators had a chance to respond.

If your organisation runs VeloCloud Orchestrator On-Prem, this is not a standard patch cycle item — it is an active incident response situation.

What Is CVE-2026-16812?

CVE-2026-16812 is an OS command injection vulnerability residing in an internal management endpoint of the VeloCloud Orchestrator On-Prem application. The flaw allows a remote, unauthenticated attacker to reach privileged internal functionality that was never intended to be externally accessible. Through this endpoint, an attacker can inject arbitrary operating system commands that execute with the privileges of the orchestrator process.

The practical consequence is devastating: an attacker with no credentials, no prior access, and no need for user interaction can achieve full remote code execution on the orchestrator host, pivot to manage all connected SD-WAN data paths, intercept network traffic flowing across the WAN, and access credentials and configuration data for all managed edge devices and gateways.

The attack vector is network (remotely exploitable), the attack complexity is low, no privileges are required, no user interaction is needed, and the impact on confidentiality, integrity, and availability is rated high across the board — which is why the CVSS 3.1 score lands at a perfect 10.0.

What Is at Stake: SD-WAN Architecture Risk

To understand why this vulnerability is particularly severe, it helps to understand what VeloCloud Orchestrator does in an enterprise environment. The orchestrator is the management brain of a VeloCloud SD-WAN deployment. It controls routing policies for all edge devices, manages encrypted overlay tunnels, and provides the single pane of glass through which network administrators configure, monitor, and troubleshoot the entire WAN.

Compromising the orchestrator means an attacker can modify routing policies to redirect traffic, insert themselves into encrypted paths, push malicious firmware or configurations to edge devices, and maintain persistence across the entire network infrastructure without touching individual devices. In a typical enterprise deployment, this translates to visibility into and control over traffic between all branch offices, remote workers, cloud environments, and data centres.

The blast radius is not limited to network disruption. Because the orchestrator holds credentials and keys for managed edge devices, a compromise can extend laterally to any network segment reachable via those edges.

Affected Versions

Only VeloCloud Orchestrator On-Prem deployments are affected by CVE-2026-16812. VeloCloud Orchestrator Hosted (Arista's SaaS offering) and VeloCloud Orchestrator Dedicated deployments were patched by Arista before the public advisory and are not vulnerable. VeloCloud Gateway and VeloCloud Edge products are also confirmed not affected.

If your organisation runs the self-hosted on-premises version of VeloCloud Orchestrator, assume you are vulnerable until you have confirmed the patch is applied.

Exploitation in the Wild: What Attackers Are Doing

Based on what is publicly known at time of writing, active exploitation of CVE-2026-16812 predates the CISA KEV addition. Arista's advisory confirms exploitation was occurring in the wild prior to the patch release, classifying this as a zero-day that was discovered through incident response rather than responsible disclosure.

Observed attack patterns align with what you would expect from a CVSS 10.0 network management vulnerability: initial exploitation of the unauthenticated command injection endpoint, rapid establishment of persistence (reverse shells, SSH key injection, cron-based backdoors), followed by credential harvesting from the orchestrator database. The three-day federal patch deadline set by CISA under BOD 26-04 reflects the urgency of the active exploitation situation.

Remediation Steps

Step 1 — Isolate the management interface immediately. If your VeloCloud Orchestrator On-Prem management interface is reachable from the internet, restrict access to management IP ranges or take the interface offline until the patch is applied. There is no legitimate reason for the orchestrator management endpoint to be publicly accessible.

Step 2 — Apply the vendor patch. Arista has released a patched version of VeloCloud Orchestrator On-Prem. Review the Arista Security Advisory for the specific build numbers and apply the update through your standard change management process — but given active exploitation, treat this as an emergency change.

Step 3 — Audit for indicators of compromise. If the orchestrator was internet-accessible prior to patching, treat it as a potentially compromised system. Review orchestrator logs for unexpected command execution, unusual administrative actions, new SSH keys or user accounts, scheduled tasks or cron entries you did not create, and outbound connections to unfamiliar IP addresses or domains.

Step 4 — Rotate credentials. After confirming the patch is applied and reviewing for IoCs, rotate all credentials stored in or accessible through the orchestrator, including API keys for managed edge devices, SNMP community strings, cloud integration credentials, and any service account passwords that the orchestrator uses.

Step 5 — Review edge device configurations. If compromise indicators are found in the orchestrator, treat edge device configurations as potentially modified. Verify that routing policies, firewall rules, and tunnel configurations match your known-good baseline.

The Bigger Picture: Management Plane Security

CVE-2026-16812 is a reminder that network management infrastructure — orchestrators, controllers, network management systems — represents a high-value, often under-tested attack surface. These systems are the keystone of network security: compromise them and every device they manage is at risk, regardless of how well those devices are hardened individually.

Traditional VAPT programmes that focus on application and perimeter security frequently miss management plane exposures. Network management interfaces, SD-WAN controllers, and similar systems need to be included explicitly in penetration testing scope — both for network isolation assessment and for application-layer vulnerability testing.

Alastor Pulse includes management infrastructure in its continuous testing scope. If you are unsure whether your network management systems have been assessed, contact us at [email protected] or visit Alastor Pulse to understand what continuous testing coverage looks like for your environment.

CVE-2026-16812 is a perfect-10 zero-day with confirmed active exploitation and a federal patch deadline that expires today — if VeloCloud Orchestrator On-Prem is in your environment, patching is not optional and isolation should already be in progress.

We use cookies to keep the platform secure and understand how our site is used. See our Security & Data policy for details.