Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Angus Taylor named as potential donor to NSW Liberal ‘Reformers’ being investigated by Icac | Independent Commission Against Corruption

    July 28, 2026

    Spain’s biggest blaze risks scorching conservatives ahead of key election year

    July 28, 2026

    Andy Burnham has made a bold start – but convincing people that change is possible will take much more | Frances Ryan

    July 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Angus Taylor named as potential donor to NSW Liberal ‘Reformers’ being investigated by Icac | Independent Commission Against Corruption
    • Spain’s biggest blaze risks scorching conservatives ahead of key election year
    • Andy Burnham has made a bold start – but convincing people that change is possible will take much more | Frances Ryan
    • Hugging Face Has a Deepfake Nudes Problem
    • NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
    • Elon Musk: Humans Will Lose Control of AI Within a Decade
    • The best way to save giant sequoias may be more fire
    • Johnson & Johnson offers to pay $5.5bn to settle baby powder lawsuits
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, July 28
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Arista patches VeloCloud Orchestrator zero-day exploited in attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 28, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks.

    The vulnerability, tracked as CVE-2026-16812, is an unauthenticated OS command injection flaw with severity scores of 10.0, the maximum score that can be given to flaws.

    VeloCloud Orchestrator, also known as VCO, is a centralized management platform used to configure, monitor, and manage VeloCloud SD-WAN deployments and associated edge devices.

    image

    According to an Arista security advisory published Monday, the vulnerability allows remote attackers to access privileged functionality that was intended only for internal use and should not be remotely accessible.

    “Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator,” Arista warned.

    The company says VCO is supposed to be exposed by default, with no configuration option that can prevent this exposure. Attackers only require network access to the VCO web interface, and no VCO tenant or operator credentials are needed to exploit the flaw.

    Arista says CVE-2026-16812 was discovered externally and is known to be actively exploited, but has not shared when the attacks began, who is behind them, or how the vulnerability is being exploited. BleepingComputer has contacted the company with these questions.

    The following VeloCloud Orchestrator on-premises versions are affected:

    • VCO 5.2.x releases before 5.2.3.14
    • VCO 6.1.x releases before 6.1.3.4
    • VCO 6.4.x releases before 6.4.2.4
    • VCO 7.0.x releases before 7.0.0.1

    VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected. VeloCloud Gateway and VeloCloud Edge products are also not vulnerable to the flaw.

    The company says the flaw is fixed in VCO versions 5.2.3.14, 6.1.3.4, and 6.4.2.4 and later. The affected software list also indicates that VCO 7.0.0.1 and later releases are not vulnerable.

    Arista warns that end-of-support software versions have not been assessed to determine if they are vulnerable. Customers running unsupported release trains are advised to contact the Arista Technical Assistance Center to discuss available upgrade options.

    The U.S. Cybersecurity and Infrastructure Security Agency has also added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog, confirming that the flaw is being used in attacks.

    CISA has ordered U.S. federal civilian executive branch agencies to mitigate the vulnerability by Thursday, July 30, 2026, as required by Binding Operational Directive 22-01.

    Indicators of compromise

    While patches are being deployed, administrators should restrict access to the VCO web interface to administrative networks, monitor for connections from known malicious IP addresses, and review recent administrator activity for unusual changes.

    Arista shared three IP addresses that were seen exploiting the vulnerability:

    • 8.19.75.217
    • 206.72.242.124
    • 206.72.242.162

    Administrators are advised to block these IP addresses and review their logs for previous connections. However, it is possible that devices could have been compromised from other IPs, so this list is not definitive.

    Organizations should review VCO logs for signs of exploitation, including:

    • Unusual web requests containing encoded characters, URL-like path components, references to local or internal services, or abnormally high request rates
    • Connections from known malicious IP addresses
    • Unexpected outbound HTTP or HTTPS traffic from the VCO host
    • Unauthorized configuration changes or privileged maintenance activity
    • Unexpected command execution, file creation, database exports, or archive files
    • Suspicious access to VCO databases, configuration data, device inventories, credentials, certificates, or cryptographic keys

    If compromise is suspected, organizations should preserve all logs and filesystem timestamps before remediation.

    Potentially affected organizations should rotate credentials, review administrator activity, validate managed devices, and consider restoring or replacing compromised instances.

    As successful exploitation can compromise both the orchestrator host and the data it manages, installing the security update may not be enough for systems that have already been breached.

    Arista warns that compromising a VeloCloud Orchestrator instance could also give attackers access to VeloCloud Edge devices as well.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Arista attacks Exploited Orchestrator Patches VeloCloud ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

    New Dysphoria DDoS botnet spreads to 200k devices worldwide

    Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials

    Adversaries Don’t Need a Zero-Day — They Read Your Rulebook

    Hackers target US firms in FastJson RCE zero-day attacks

    What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Angus Taylor named as potential donor to NSW Liberal ‘Reformers’ being investigated by Icac | Independent Commission Against Corruption

    July 28, 2026

    Spain’s biggest blaze risks scorching conservatives ahead of key election year

    July 28, 2026

    Andy Burnham has made a bold start – but convincing people that change is possible will take much more | Frances Ryan

    July 28, 2026

    Hugging Face Has a Deepfake Nudes Problem

    July 28, 2026
    Latest Posts

    The Western Myth of Russian Greatness – Foreign Policy

    July 21, 2026

    Defence stocks rally as John Healey appointed chancellor; UK borrows less than expected in June – business live | Business

    July 21, 2026

    You Pay for Internet Service in Empty Buildings on Alaska’s Adak Island — ProPublica

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Angus Taylor named as potential donor to NSW Liberal ‘Reformers’ being investigated by Icac | Independent Commission Against Corruption

    July 28, 2026

    Spain’s biggest blaze risks scorching conservatives ahead of key election year

    July 28, 2026

    Andy Burnham has made a bold start – but convincing people that change is possible will take much more | Frances Ryan

    July 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.