Critical Arista VeloCloud Orchestrator RCE (CVE-2026-16812)
Arista disclosed CVE-2026-16812, a CVSS 10.0 operating-system command injection in on-premises VeloCloud Orchestrator (VCO) that is being actively exploited. Successful exploitation can give remote attackers privileged control of the orchestrator and potentially the VeloCloud Edge devices it manages. Arista published fixed on-prem builds (5.2.3.14, 6.1.3.4, 6.4.2.4, 7.0.0.1), advised network blocks for three IoC IPs (8.19.75.217, 206.72.242.124, 206.72.242.162), and recommended restricting VCO web access and preserving logs for forensic analysis. CISA added the flaw to its Known Exploited Vulnerabilities catalog with a July 30, 2026 FCEB patch deadline. The article also notes related KEV additions for Fortinet FortiOS (CVE-2025-68686) and Alibaba Fastjson (CVE-2026-16723).
- •Arista disclosed CVE-2026-16812, a CVSS 10.0 OS command injection in on-premises VeloCloud Orchestrator.
- •The vulnerability was publicly reported and already under active exploitation as of Arista's advisory published July 27, 2026.
- •Arista released fixed on-prem VCO builds: 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1; hosted and dedicated instances were already patched by Arista.
