Active Exploitation Alert: Arista VeloCloud Orchestrator CVE-2026-16812 Command Injection Vulnerability Enables Remote Compromise

Active Exploitation Alert: Arista VeloCloud Orchestrator CVE-2026-16812 Command Injection Vulnerability Enables Remote Compromise

Executive Summary

A critical vulnerability, identified as CVE-2026-16812, has been discovered and is being actively exploited in the wild, targeting the Arista VeloCloud Orchestrator On-Prem platform. This command injection flaw enables remote, unauthenticated attackers to execute arbitrary operating system commands on the orchestrator host, leading to a full compromise of the orchestrator and all managed SD-WAN data. The vulnerability is now included in the CISA Known Exploited Vulnerabilities (KEV) Catalog, underscoring its severity and the urgency for immediate remediation. Organizations leveraging Arista VeloCloud Orchestrator are at significant risk of data breach, service disruption, and lateral movement within their networks if this flaw remains unaddressed.

Threat Actor Profile

While no specific advanced persistent threat (APT) group or criminal syndicate has been publicly attributed to the exploitation of CVE-2026-16812 as of this report, the tactics, techniques, and procedures (TTPs) observed align with those commonly employed by both state-sponsored actors and financially motivated ransomware groups. These actors typically target network infrastructure components to gain persistent access, exfiltrate sensitive data, and facilitate further attacks such as ransomware deployment or espionage. The opportunistic nature of the exploitation, combined with the criticality of the affected product, suggests that a broad spectrum of threat actors—including those with high technical sophistication—are likely to leverage this vulnerability.

Technical Analysis of Malware/TTPs

The vulnerability in Arista VeloCloud Orchestrator On-Prem is classified as an OS command injection (CWE-78), allowing attackers to inject and execute arbitrary shell commands via crafted HTTP requests to the orchestrator’s web interface. The flaw exists due to improper neutralization of special elements in user-supplied input, which is subsequently passed to the underlying operating system shell without adequate sanitization.

Attackers exploit this flaw by sending specially crafted HTTP requests to exposed orchestrator endpoints. These requests embed malicious payloads that are interpreted by the orchestrator’s backend as legitimate commands, executed with the privileges of the orchestrator system user. This grants attackers the ability to:

  • Install persistent backdoors or web shells,
  • Exfiltrate sensitive SD-WAN configuration data,
  • Manipulate or disrupt orchestrator operations,
  • Pivot laterally within the network to compromise additional assets.

The exploitation chain typically follows the MITRE ATT&CK framework techniques: T1190 (Exploit Public-Facing Application) for initial access, T1059 (Command and Scripting Interpreter) for command execution, and T1569.002 (System Services: Service Execution) for persistence and lateral movement.

No specific malware families or exploit kits have been directly associated with this vulnerability as of this writing. However, the attack surface and exploitation method are consistent with those leveraged by both automated botnets and targeted human-operated campaigns.

Exploitation in the Wild

The addition of CVE-2026-16812 to the CISA KEV Catalog on July 27, 2026, confirms that exploitation is not theoretical but actively occurring. Multiple security advisories and threat intelligence sources, including SecurityOnline.info and WindowsForum, have reported ongoing attacks targeting unpatched Arista VeloCloud Orchestrator instances. These attacks are characterized by their unauthenticated nature, meaning that any internet-exposed orchestrator is at risk, regardless of internal access controls.

Observed exploitation involves attackers scanning for publicly accessible orchestrator endpoints, delivering payloads via HTTP POST or GET requests, and leveraging the resulting command execution to establish persistence or further compromise the environment. The lack of authentication requirements significantly lowers the barrier to entry for attackers, increasing the likelihood of widespread exploitation.

Victimology and Targeting

Victims of this vulnerability are organizations deploying Arista VeloCloud Orchestrator On-Prem to manage their SD-WAN infrastructure. This includes enterprises across sectors such as finance, healthcare, manufacturing, government, and critical infrastructure, where SD-WAN solutions are integral to network operations. The vulnerability is particularly impactful for organizations with orchestrators exposed to the public internet, as these are the primary targets for automated and targeted exploitation campaigns.

While no sector-specific targeting has been confirmed, the nature of SD-WAN orchestrators as central management points makes them attractive to attackers seeking to maximize impact. Compromise of the orchestrator can lead to downstream attacks on branch offices, remote sites, and connected cloud environments, amplifying the potential damage.

Mitigation and Countermeasures

Immediate action is required to mitigate the risk posed by CVE-2026-16812. Organizations should:

Apply the latest security patches provided by Arista as detailed in Security Advisory 0144. Fixed versions include 4.5.0.2 and later, 4.4.2.1 and later (4.4.x branch), 4.3.3.3 and later (4.3.x branch), and 4.2.4.2 and later (4.2.x branch). Any orchestrator running a prior version is vulnerable and must be updated without delay.

Remove all Arista VeloCloud Orchestrator instances from public internet exposure until patched. Restrict access to trusted management networks and implement strong network segmentation to limit lateral movement.

Monitor orchestrator hosts for indicators of compromise, including unusual outbound connections, unexpected processes, unauthorized changes to SD-WAN configurations, and anomalous authentication attempts.

Review and follow guidance from CISA BOD 26-04 for prioritizing security updates and conducting forensic triage on potentially compromised systems.

Implement robust logging and alerting on orchestrator systems to detect suspicious activity. Regularly review logs for evidence of exploitation attempts or successful compromise.

Conduct a comprehensive security review of all SD-WAN infrastructure, ensuring that all components are up to date and properly secured.

References

Arista Security Advisory 0144: https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144

CISA KEV Catalog Entry: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search=%22command+injection%22&field_date_added_wrapper=all&field_cve=&sort_by=field_date_added&items_per_page=All&url=

NVD Entry: https://nvd.nist.gov/vuln/detail/CVE-2026-16812

SecurityOnline.info: https://securityonline.info/cisa-kev-arista-velocloud-fortios/

WindowsForum: https://windowsforum.com/security-alerts.84/cisa-kev-adds-velocloud-orchestrator-rce-and-fortios-ssl-vpn-flaw.440641/

About Rescana

Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to assess, monitor, and mitigate cyber risks across their extended supply chain. Our advanced threat intelligence and automation capabilities empower security teams to proactively identify vulnerabilities, prioritize remediation, and ensure compliance with industry standards. For more information about how Rescana can help safeguard your organization’s digital ecosystem, or for any questions regarding this advisory, please contact us at info@rescana.com.