Hackers Are Actively Exploiting a Critical VeloCloud Orchestrator Vulnerability
Want more insights like this?
A maximum-severity command injection flaw (CVE-2026-16812, CVSS 10.0) in on-premises Arista VeloCloud Orchestrator — formerly VeloCloud Orchestrator by Broadcom — is being actively exploited in the wild, and was exploited as a zero-day. Attackers need no credentials, just network access to the VCO web interface, to take control of the orchestrator and the SD-WAN fabric it manages.
Affected versions span VCO 5.2.x, 6.1.x, 6.4.x and 7.0.x. Fixes are available in 5.2.3.14, 6.1.3.4, 6.4.2.4 and 7.0.0.1. Hosted and Dedicated VCO instances were already patched by Arista.
Three attacker IPs have been identified: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Admins should patch immediately, block those addresses and restrict web interface access. Arista also requires rotating credentials and validating device state after remediation — not only where compromise is suspected.
Source: Cybersecurity News