🔴 Critical | Source: CISA Known Exploited Vulnerabilities
A critical OS command injection vulnerability in Arista VeloCloud Orchestrator (VCO) On-Prem allows a remote attacker to execute privileged commands on the host system without authentication. Successful exploitation could give an attacker full control over the orchestrator, compromising all SD-WAN network management, configuration data, and connected infrastructure. This is actively exploited according to CISA, with remediation required by 30 July 2026.
Security Architect’s Take: Immediately audit all internet-exposed VeloCloud Orchestrator instances and apply Arista’s patch or mitigation — if patching is not yet possible, restrict management plane access to trusted IP ranges via firewall rules and review VCO audit logs for anomalous command execution or privilege escalation activity.
Original advisory: CVE-2026-16812: Arista VeloCloud Orchestrator