Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
Arista has released patches for a maximum-severity vulnerability in its VeloCloud Orchestrator software after confirming attackers were already exploiting it, prompting the US Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities catalogue. The bug affects the on-premises, self-hosted version of the orchestrator, which enterprises use to centrally manage VeloCloud software-defined wide area networks linking branch offices, datacentres and cloud environments, and its unauthenticated, remote nature makes it especially dangerous.
Tracked as CVE-2026-16812, the flaw is an OS command injection vulnerability with a perfect CVSS score of 10.0 that lets an attacker with no credentials reach privileged internal functionality via the web interface, potentially compromising both the orchestrator and connected VeloCloud Edge devices. Arista said the on-prem orchestrator is exposed by default with no way to fully close off that exposure, and while it has published three IP addresses linked to attacks, it has not disclosed who is behind them, when the campaign began, or how many customers were affected. Hosted and dedicated orchestrator customers were already patched before the advisory, and fixes are now available in versions 5.2.3.14, 6.1.3.4, 6.4.2.4 and 7.0.0.1, with Arista urging anyone on older releases to upgrade immediately.
- Arista's VeloCloud Orchestrator flaw scores a maximum 10.0 severity rating.
- Attackers already exploiting it before a patch was released.
- CISA lists it as actively exploited; admins urged to upgrade now.