A critical security vulnerability affecting on-premises versions of Arista VeloCloud Orchestrator (VCO) is currently being exploited in the wild.
This vulnerability, identified as CVE-2026-16812 (with a CVSS score of 10.0), involves operating system command injection that could enable arbitrary code execution.
According to an advisory released by Arista on Monday, “VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host.”
“Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible,” the company added.
Arista, an American network equipment manufacturer, stated that the issue has already been resolved in hosted and dedicated versions of VCO ahead of time. The following versions are vulnerable:
- VCO 5.2.x releases prior to 5.2.3.14
- VCO 6.1.x releases prior to 6.1.3.4
- VCO 6.4.x releases prior to 6.4.2.4
- VCO 7.0.x releases prior to 7.0.0.1
Arista confirmed that the vulnerability was discovered externally and is known to be actively exploited, but did not disclose when it was reported or how many customers might have been affected by the malicious cyber activity leveraging the flaw.
As indicators of compromise (IoCs), the company provided three IP addresses believed to be involved in the attacks, advising customers to block these addresses and check their logs for any signs of their presence:
- 8.19.75.217
- 206.72.242.124
- 206.72.242.162
“If compromise is suspected, operators should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible,” the advisory stated.
If immediate updating to a patched VCO version is not feasible, it is recommended to limit access to the VCO web interface to trusted administrative networks, monitor the VCO for access from known malicious IP addresses, check for unexpected outbound network activity from the VCO host, and review recent administrator actions for any unexpected changes.
Arista noted, “Compromises to the VCO platform may allow attackers access to the VeloCloud Edge devices as well.” This could involve credential rotation, reviewing administrator activity, validating the state of managed devices, and restoring or replacing affected orchestrator instances from trusted sources.
This situation has led the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to include the vulnerability in its Known Exploited Vulnerabilities (KEV) catalog, mandating that Federal Civilian Executive Branch (FCEB) agencies implement the patch by July 30, 2026.
News of the active exploitation of CVE-2026-16812 coincides with the agency’s addition of a medium-severity vulnerability affecting Fortinet FortiOS SSL-VPN (CVE-2025-68686, CVSS score: 5.3) to the KEV catalog, which also cites evidence of active exploitation. Fortinet had patched this issue earlier in February.
Fortinet stated in an alert at the time, “An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiOS SSL-VPN may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at the file system level.”
Currently, there are no details available regarding how the vulnerability is being exploited in the wild, the extent of the attacks, or the identities of those responsible. Federal agencies have until August 10, 2026, to apply the necessary patches.
Another security vulnerability that has come under attack is CVE-2026-16723 (CVSS score: 9.0), a critical issue in Alibaba’s Fastjson library that could permit remote code execution without user interaction or elevated privileges.
Source: Original article
