Hackers Are Actively Exploiting a Critical VeloCloud Orchestrator Vulnerability
Urgent patch needed for critical VeloCloud flaw (CVE-2026-16812) actively exploited. Secure your systems now. Block IPs and rotate credentials.
By
Content Team
ON THIS PAGE
Want more insights like this?
Subscribe to our newsletter to get the latest software protection strategies delivered to your inbox.
By submitting your email, you consent to Codekeeper contacting you and agree to our privacy policy.
A maximum-severity command injection flaw (CVE-2026-16812, CVSS 10.0) in on-premises VeloCloud Orchestrator is being actively exploited in the wild. Attackers need no credentials — just network access to the VCO web interface — to hijack the orchestrator and potentially the SD-WAN Edge devices it manages.
Affected versions span VCO 5.2.x, 6.1.x, 6.4.x, and 7.0.x. Patches are available now. Three attacker IPs have been identified: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Admins should patch immediately, block those addresses, restrict web interface access, and rotate credentials if compromise is suspected.
Source: Cybersecurity News
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo