LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-16812: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 27, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 30, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog on Jul 27, 2026, with a federal patch deadline of Jul 30, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful…

CVE-2026-16812 is an OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem. A remote attacker who can reach the affected interface may abuse it to run commands in a privileged context on the orchestrator host, which can put the confidentiality, integrity, and availability of the orchestrator and the data it manages at risk.

SD-WAN orchestrators sit at the center of network control and visibility. Compromise of that plane can affect configuration, telemetry, and connectivity decisions across sites. Confirm exact scope, fixed builds, and exposure conditions against the vendor advisory before acting.

How it works

This issue is classified as CWE-78 (OS command injection). In products of this class, user-controlled input is passed into a shell or system command without sufficient validation or separation of data from code. An attacker who can supply that input—often via an authenticated or network-reachable management path—may cause the application to execute attacker-chosen operating-system commands with the privileges of the service account.

Public detail for this CVE does not describe the exact request path, parameter, or authentication requirement. In general, successful abuse of command injection on an orchestrator can yield host-level access, lateral movement into management networks, and tampering with or disclosure of configurations and operational data. Do not assume unauthenticated remote code execution or any specific exploit chain without confirmation from the vendor advisory and your own testing in a lab.

Am I affected? How to find it in your systems

Arista VeloCloud Orchestrator On-Prem is typically deployed as a central management component for VeloCloud SD-WAN environments—often in a data center, private cloud, or dedicated management VLAN, and sometimes with administrative access from the internet or partner networks. Inventory every on-premises VCO instance, including lab, DR, and forgotten appliances.

How to remediate

Patch first. Apply the vendor-supplied update or mitigation package for Arista VeloCloud Orchestrator On-Prem exactly as described in the official advisory. Validate the installed version after upgrade and retain evidence for change control and any regulatory obligations (including CISA BOD 26-04 prioritization where it applies to your environment).

If you can't patch immediately

Until the vendor fix is installed, reduce exposure and increase detection. Compensating controls do not replace the patch.

If your data may have been exposed

Actively exploited management-plane flaws can lead to full compromise of the orchestrator and the configurations and operational data it holds. Ransomware use is not documented for this CVE in the provided facts; still treat confirmed exploitation as a security incident: isolate affected hosts, preserve volatile and disk evidence, rotate secrets, and follow your forensics and notification procedures (including any CISA forensics triage expectations that apply to you).

If you need a quick external check on whether email addresses tied to your organization appear in known breach datasets, you can run a free exposure scan of those addresses as one input to your investigation—not as proof that this CVE was or was not used against you.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedArista · VeloCloud Orchestrator
WeaknessCWE-78
Added to CISA KEVJul 27, 2026
Federal patch deadlineJul 30, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities