Ethical Hacking News
A critical vulnerability has been discovered in Arista VeloCloud Orchestrator, allowing remote attackers to access privileged functionality and impact the security and integrity of affected systems. Organizations must take immediate action to address this issue and protect themselves against potential exploitation.
A critical vulnerability (CVE-2026-16812) has been discovered in Arista VeloCloud Orchestrator (VCO), rated at 10.0 on the Common Vulnerability Scoring System (CVSS). The vulnerability allows remote attackers to access privileged internal functionality, compromising system security and integrity. Arista has addressed hosted and dedicated versions but on-premises versions are still vulnerable; specific versions affected include 5.2.x, 6.1.x, 6.4.x, and 7.0.x releases prior to certain patches. The vulnerability is actively exploited by attackers and customers should block known malicious IP addresses and monitor logs for signs of compromise. Customers are advised to limit access to the VCO web interface and monitor network activity if immediate updating is not possible. The vulnerability may also allow access to VeloCloud Edge devices, including credential rotation and review of administrator activity.
The cybersecurity landscape has been shaken to its core with the revelation of a critical vulnerability impacting on-premises versions of Arista VeloCloud Orchestrator (VCO). This alarming development, tracked as CVE-2026-16812, has already come under active exploitation in the wild. The severity of this flaw cannot be overstated; it is rated at 10.0 on the Common Vulnerability Scoring System (CVSS), indicating that it poses a significant threat to the security and integrity of affected systems.
The vulnerability in question is a case of operating system command injection, which could potentially allow a remote attacker to access privileged internal functionality and impact the VCO host. This, in turn, could compromise the confidentiality, integrity, and availability of the orchestrator and data managed by it. It is worth noting that this functionality was intended for internal use only and is not intended to be remotely accessible.
Arista has acknowledged that the issue has already been addressed in hosted and dedicated versions of VCO in advance. However, on-premises versions are still vulnerable, with versions 5.2.x releases prior to 5.2.3.14, VCO 6.1.x releases prior to 6.1.3.4, VCO 6.4.x releases prior to 6.4.2.4, and VCO 7.0.x releases prior to 7.0.0.1 being particularly affected.
The vulnerability was externally discovered and is known to be actively exploited by attackers. Arista has shared a set of three IP addresses that are responsible for conducting the attacks: 8.19.75.217, 206.72.242.124, and 206.72.242.162. It is recommended that customers block these IPs and review their logs to determine if they are present.
If compromise is suspected, operators should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible. In the event that immediate updating to a fixed VCO release is not an option, it is suggested that customers restrict access to the VCO web interface to trusted administrative networks, monitor the VCO for access from known malicious source IPs, check for unexpected outbound network activity from the VCO host, and review recent administrator activity for unexpected changes.
Furthermore, Arista has warned that compromises to the VCO platform may allow attackers to access the VeloCloud Edge devices as well. This could include credential rotation, review of administrator activity, validation of managed device state, and restoration or replacement of affected orchestrator instances from trusted sources.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patch by July 30, 2026. This move underscores the gravity of the situation and highlights the importance of addressing this vulnerability without delay.
In light of these developments, it is essential for organizations that rely on Arista VeloCloud Orchestrator to take immediate action to protect themselves against this critical flaw. By following the recommended remediation steps and applying the necessary patches, they can significantly reduce the risk of falling victim to this vulnerability.
Related Information:
https://www.ethicalhackingnews.com/articles/A-Critical-Flaw-Exposed-Arista-VeloCloud-Orchestrator-Command-Injection-Vulnerability-Impacts-On-Premises-Versions-ehn.shtml
https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html
Published: Tue Jul 28 01:07:50 2026 by llama3.2 3B Q4_K_M