Executive Summary
Arista Networks has issued an urgent security advisory regarding a critical zero-day vulnerability in its on-premises VeloCloud Orchestrator (VCO) product. The flaw, tracked as CVE-2026-16812, is an unauthenticated OS command injection vulnerability with a maximum CVSS score of 10.0, indicating the highest level of severity. This vulnerability is being actively exploited in the wild, enabling remote attackers to execute arbitrary commands with elevated privileges on affected systems. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog and has mandated immediate remediation for federal agencies. Organizations using vulnerable versions of VCO are at significant risk of compromise, including potential lateral movement to managed edge devices and exposure of sensitive configuration data. Immediate patching and incident response actions are strongly advised.
Threat Actor Profile
At this time, there is no public attribution to a specific advanced persistent threat (APT) group or criminal organization exploiting CVE-2026-16812. The exploitation activity observed so far is opportunistic, targeting exposed VCO instances accessible over the internet or from untrusted networks. The attack does not require authentication, making it attractive to a broad spectrum of threat actors, from state-sponsored groups to financially motivated cybercriminals. The use of multiple malicious IP addresses and the rapid weaponization of the exploit suggest a high level of automation and scanning, consistent with both targeted and mass exploitation campaigns. The lack of a public proof-of-concept (PoC) exploit at the time of reporting indicates that the attackers may be leveraging privately developed or acquired exploit code.
Technical Analysis of Malware/TTPs
The vulnerability in Arista VeloCloud Orchestrator arises from improper input validation in the web interface, allowing unauthenticated remote attackers to inject and execute arbitrary operating system commands. The attack vector is purely network-based; an attacker only needs access to the VCO web interface, with no requirement for valid credentials. Exploitation is achieved by crafting specially formed HTTP requests containing malicious payloads that are processed by the vulnerable backend component. Upon successful exploitation, the attacker gains the ability to execute commands with the privileges of the VCO application, which typically runs with elevated permissions on the orchestrator host.
Observed tactics, techniques, and procedures (TTPs) include the use of encoded or obfuscated payloads to bypass basic input filtering, rapid enumeration of accessible VCO instances, and the deployment of post-exploitation tools for persistence and lateral movement. Attackers have been seen leveraging the initial foothold to access sensitive configuration files, extract credentials, and potentially pivot to managed VeloCloud Edge devices. The exploitation chain aligns with several MITRE ATT&CK techniques: Exploit Public-Facing Application (T1190), Command and Scripting Interpreter (T1059), Valid Accounts (T1078) if credentials are harvested, Indicator Removal on Host (T1070), Data Manipulation (T1565), and Data Destruction (T1485).
No specific malware family has been publicly associated with these attacks, but the observed activity includes the execution of shell commands, creation of archive files, and exfiltration of configuration data. The attackers may also attempt to cover their tracks by deleting logs or modifying timestamps.
Exploitation in the Wild
Active exploitation of CVE-2026-16812 was detected prior to public disclosure, classifying this as a true zero-day event. Multiple security vendors and government agencies have reported in-the-wild attacks targeting unpatched VCO instances. The exploitation requires only network access to the VCO web interface, making internet-exposed or poorly segmented deployments especially vulnerable.
Malicious activity observed includes unauthorized access to the orchestrator, execution of arbitrary commands, extraction of sensitive data, and attempts to compromise downstream edge devices. Attackers have utilized a set of known malicious IP addresses, including 8.19.75.217, 206.72.242.124, and 206.72.242.162, to scan for and exploit vulnerable systems. The U.S. CISA has issued a binding operational directive requiring all federal agencies to patch affected systems by July 30, 2026, underscoring the urgency and severity of the threat.
Indicators of compromise (IOCs) include unusual web requests with encoded characters or references to internal services, abnormally high request rates, unexpected outbound traffic from the VCO host, unauthorized configuration changes, and suspicious access to databases, credentials, or cryptographic keys.
Victimology and Targeting
The exploitation of CVE-2026-16812 appears to be broad and opportunistic, with no confirmed targeting of specific sectors, geographies, or organizations. However, the inclusion of the vulnerability in the CISA KEV catalog and the rapid response from U.S. federal agencies suggest that government, critical infrastructure, and large enterprise environments are at heightened risk. Any organization operating on-premises VeloCloud Orchestrator deployments that are accessible from untrusted networks is a potential target.
The attack surface is defined by the exposure of the VCO web interface. Organizations with internet-facing or poorly segmented VCO instances are most at risk. There is no evidence at this time of targeting based on industry vertical, but the potential for lateral movement to managed edge devices increases the risk profile for organizations with distributed network architectures.
Mitigation and Countermeasures
Immediate action is required to mitigate the risk posed by CVE-2026-16812. Organizations must upgrade to the latest fixed versions of VeloCloud Orchestrator: 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1, depending on the deployment. Hosted and dedicated VCO deployments managed by Arista have already been patched and are not affected. It is critical to restrict access to the VCO web interface, ensuring it is only reachable from trusted administrative networks and never exposed directly to the internet.
Organizations should block known malicious IP addresses at the network perimeter and review VCO and network logs for evidence of exploitation or suspicious activity. Credential hygiene is essential; all credentials, certificates, and cryptographic keys managed by the VCO should be rotated if compromise is suspected. The integrity of managed VeloCloud Edge devices should be validated, as attackers may attempt to pivot from the orchestrator to downstream assets.
If compromise is suspected, organizations should preserve all relevant logs and filesystem timestamps before initiating remediation. Consider restoring affected systems from known-good backups or performing a full reinstallation. Engage incident response teams as necessary to contain and eradicate the threat.
References
- Arista Security Advisory 0144
- BleepingComputer: Arista patches VeloCloud Orchestrator zero-day exploited in attacks
- SecurityWeek: Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
- CISA KEV Catalog
- MITRE ATT&CK T1190, T1059, T1078, T1070, T1565, T1485
About Rescana
Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to continuously monitor, assess, and mitigate cyber risks across their extended supply chain. Our advanced threat intelligence and automation capabilities empower security teams to proactively identify vulnerabilities, respond to emerging threats, and ensure compliance with regulatory requirements. For more information about how Rescana can help strengthen your organization’s cyber resilience, or for any questions regarding this advisory, please contact us at info@rescana.com.



