Executive Summary
Arista Networks has issued an urgent security advisory regarding a critical zero-day vulnerability in its on-premises VeloCloud Orchestrator (VCO) product. This vulnerability, tracked as CVE-2026-16812, is an unauthenticated command injection flaw that is currently being exploited in the wild. Attackers leveraging this vulnerability can gain remote, unauthenticated access to the underlying operating system, leading to full compromise of the orchestrator and potentially all managed devices. The severity of this vulnerability is rated as critical (CVSS 10.0), and immediate patching is strongly advised. Organizations using affected versions of Arista VCO must act without delay to mitigate the risk of compromise, as exploitation requires only network access to the VCO web interface and does not require valid credentials.
Threat Actor Profile
At this time, there is no public attribution to a specific advanced persistent threat (APT) group or criminal organization exploiting CVE-2026-16812. The exploitation activity has been observed by Arista, corroborated by the Cybersecurity and Infrastructure Security Agency (CISA), and reported by multiple security news outlets. The lack of attribution suggests that multiple threat actors, including both opportunistic cybercriminals and potentially state-sponsored groups, may be leveraging this vulnerability. The attack surface is broad, as the exploit requires only network access to the vulnerable web interface, making it attractive for both targeted and indiscriminate attacks. The inclusion of this vulnerability in the CISA Known Exploited Vulnerabilities Catalog further underscores its active exploitation and the urgency for remediation.
Technical Analysis of Malware/TTPs
The vulnerability in Arista VeloCloud Orchestrator is an unauthenticated operating system command injection flaw. Specifically, the flaw resides in the web interface of the on-premises VCO, where user-supplied input is not properly sanitized before being passed to a system shell. This allows an attacker to craft specially crafted HTTP requests containing malicious payloads that are executed with the privileges of the orchestrator process.
The attack vector is purely network-based. An attacker does not require valid credentials or prior access to the system. By sending a malicious request to the VCO web interface, the attacker can execute arbitrary commands on the underlying operating system. This can lead to a range of post-exploitation activities, including but not limited to:
- Downloading and executing additional malware or remote access tools
- Exfiltrating sensitive configuration data, credentials, and cryptographic keys
- Modifying orchestrator settings to facilitate lateral movement to managed VeloCloud Edge devices
- Establishing persistence through scheduled tasks, backdoors, or web shells
- Disabling security controls or erasing forensic evidence
Observed tactics, techniques, and procedures (TTPs) align with the following MITRE ATT&CK techniques: T1190 (Exploit Public-Facing Application), T1059 (Command and Scripting Interpreter), T1078 (Valid Accounts) if credentials are harvested, and T1003 (OS Credential Dumping) for post-exploitation credential access.
No public proof-of-concept exploit code has been released as of this report, but exploitation in the wild has been confirmed. Attackers are leveraging the vulnerability to gain initial access, followed by rapid privilege escalation and lateral movement within affected environments.
Exploitation in the Wild
Active exploitation of CVE-2026-16812 has been confirmed by Arista, CISA, and independent security researchers. Attackers are scanning for exposed VCO web interfaces and launching unauthenticated command injection attacks. The exploitation does not require any form of authentication, making any internet-exposed or poorly segmented VCO instance a high-value target.
Indicators of compromise (IOCs) associated with observed exploitation include connections from the following IP addresses: 8.19.75.217, 206.72.242.124, and 206.72.242.162. These IPs have been identified as sources of malicious activity targeting vulnerable VCO instances, but organizations should be aware that additional IPs may be involved as threat actors rotate infrastructure.
Signs of exploitation may include unusual web requests with encoded characters or references to internal services, high volumes of requests to the VCO web interface, unexpected outbound HTTP/HTTPS traffic from the orchestrator host, unauthorized configuration changes, evidence of command execution, creation of suspicious files or archives, and access to sensitive databases or cryptographic material.
The potential impact of successful exploitation is severe. Attackers can achieve full compromise of the orchestrator host, exfiltrate sensitive data, manipulate managed devices, and establish persistent access for future operations. In environments where the orchestrator manages critical network infrastructure, the risk extends to the broader enterprise network.
Victimology and Targeting
While there is no public attribution to specific sectors or geographies, the urgent directive from CISA to U.S. federal agencies and the inclusion of CVE-2026-16812 in the Known Exploited Vulnerabilities Catalog indicate that government, critical infrastructure, and large enterprise sectors are at heightened risk. The attack surface includes any organization running vulnerable on-premises deployments of Arista VeloCloud Orchestrator.
The vulnerability does not affect hosted or dedicated VCO deployments, which were patched prior to public disclosure, nor does it impact VeloCloud Gateway or Edge products. However, organizations with hybrid deployments or legacy on-premises orchestrators are particularly exposed. The lack of authentication required for exploitation means that any internet-exposed VCO instance is a potential target, regardless of industry or geography.
Mitigation and Countermeasures
Immediate action is required to mitigate the risk posed by CVE-2026-16812. Organizations must upgrade to the following fixed versions of Arista VeloCloud Orchestrator: 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1 (or later). Patching should be prioritized for all on-premises deployments, with particular attention to instances exposed to the internet or accessible from untrusted networks.
In addition to patching, organizations should restrict access to the VCO web interface to trusted administrative networks only, using network segmentation and firewall rules to limit exposure. The malicious IP addresses identified above should be blocked at the network perimeter, and security teams should review VCO logs for evidence of exploitation, including connections from these IPs and signs of unauthorized activity.
Credential hygiene is critical. All credentials associated with the orchestrator and managed devices should be rotated, and administrator activity should be reviewed for signs of compromise. If exploitation is suspected, organizations should preserve all relevant logs and filesystem timestamps before initiating remediation, as attackers may attempt to erase evidence.
It is important to note that patching alone may not be sufficient if the orchestrator has already been compromised. In such cases, a full incident response investigation is warranted, including forensic analysis, containment, eradication of attacker persistence mechanisms, and validation of the integrity of managed devices.
References
- Arista Security Advisory 0144
- BleepingComputer: Arista patches VeloCloud Orchestrator zero-day exploited in attacks
- SecurityWeek: Arista Urges Immediate Patching of Exploited VCO Zero-Day
- CISA Known Exploited Vulnerabilities Catalog
- NVD: CVE-2026-16812
- LinkedIn: A cybersecurity professional describes attackers exploiting Arista VeloCloud Orchestrator
About Rescana
Rescana is a leader in third-party risk management (TPRM) and cyber risk intelligence. Our platform empowers organizations to continuously monitor, assess, and mitigate cyber risks across their extended supply chain and digital ecosystem. By leveraging advanced analytics and real-time threat intelligence, Rescana enables proactive defense against emerging threats and supports robust incident response capabilities. For more information about how Rescana can help your organization strengthen its cyber resilience, please contact us at info@rescana.com.



