<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Hackers Are Actively Exploiting a Critical VeloCloud Orchestrator Vulnerability

Urgent patch needed for critical Arista VeloCloud flaw (CVE-2026-16812) actively exploited. Secure your systems now. Block IPs and rotate credentials.
Content Team

A maximum-severity command injection flaw (CVE-2026-16812, CVSS 10.0) in on-premises Arista VeloCloud Orchestrator — formerly VeloCloud Orchestrator by Broadcom — is being actively exploited in the wild, and was exploited as a zero-day. Attackers need no credentials, just network access to the VCO web interface, to take control of the orchestrator and the SD-WAN fabric it manages.

Affected versions span VCO 5.2.x, 6.1.x, 6.4.x and 7.0.x. Fixes are available in 5.2.3.14, 6.1.3.4, 6.4.2.4 and 7.0.0.1. Hosted and Dedicated VCO instances were already patched by Arista.

Three attacker IPs have been identified: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Admins should patch immediately, block those addresses and restrict web interface access. Arista also requires rotating credentials and validating device state after remediation — not only where compromise is suspected.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo