ZeroDayAlert

CVE-2026-16812: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Arista VeloCloud Orchestrator Added to KEV 2026-07-27 Federal due 2026-07-30 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Arista VeloCloud Orchestrator On-Prem deployments are affected by an OS command injection vulnerability. The flaw allows remote attackers to execute arbitrary commands with privileges on the orchestrator host, potentially compromising confidentiality, integrity and availability of the orchestrator and the data it manages. The record does not specify affected version numbers or deployment ranges.

How to check whether this touches you

  • Search your asset inventory for VeloCloud Orchestrator On-Prem instances; cloud-hosted VCO may be out of scope depending on your deployment model.
  • Determine network reachability: check whether your VCO instances are directly accessible from untrusted networks (internet, third-party networks, or guest segments).
  • Query running instances for their version number through administrative tools or API queries; version alone is not definitive proof of exposure, as backported patches exist.
  • Review firewall and load-balancer rules to understand which network paths lead to your VCO administrative or API endpoints.
  • Check your change-management records for recent patches or mitigations already applied by Arista.

What to do

  1. Contact Arista immediately for patch availability and detailed remediation guidance specific to your version.
  2. If a patch is available and can be deployed within your change window, prioritise its application according to CISA BOD 26-04 guidance.
  3. If no patch is available or deployment is delayed, reduce exposure by restricting network access to VCO administrative interfaces to trusted networks only; disable or isolate any external-facing API endpoints until mitigation is confirmed.
  4. Enable logging of all command execution and administrative actions on the VCO host and its network interfaces; retain logs for at least 90 days.
  5. If you cannot apply mitigations or if the product is not essential, evaluate discontinuation of use as recommended in the required action.
  6. Escalate to your security operations and infrastructure teams; this is a CISA-tracked vulnerability with a federal remediation deadline.

If you find you were exposed

Exploitation of OS command injection typically occurs before public disclosure, so assume that if your VCO instance was reachable and unpatched during the interval between initial compromise and your remediation, it may have been exploited. Review VCO host logs, system logs, and network traffic for anomalous process execution, outbound connections, or data exfiltration dating back at least 90 days before your patch date. Check for persistence mechanisms such as scheduled tasks, new user accounts, or modified authentication credentials. If logs are unavailable or insufficient, engage Arista support or a forensic service to assist with timeline reconstruction.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-16812 is being exploited. It cannot tell you whether VeloCloud Orchestrator is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →