A maximum-severity command injection flaw (CVE-2026-16812, CVSS 10.0) in on-premises VeloCloud Orchestrator is being actively exploited in the wild. Attackers need no credentials — just network access to the VCO web interface — to hijack the orchestrator and potentially the SD-WAN Edge devices it manages.
Affected versions span VCO 5.2.x, 6.1.x, 6.4.x, and 7.0.x. Patches are available now. Three attacker IPs have been identified: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Admins should patch immediately, block those addresses, restrict web interface access, and rotate credentials if compromise is suspected.
Source: Cybersecurity News