Affected Systems
Arista VeloCloud Orchestrator (VCO) on-premises versions: 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.2.4, and 7.0.x prior to 7.0.0.1. Hosted and dedicated VCO versions already patched. Compromise may extend to managed VeloCloud Edge devices.
Exploitation Status
Active exploitation confirmed in the wild. Arista has disclosed three attacker IP addresses (8.19.75.217, 206.72.242.124, 206.72.242.162). CISA added CVE-2026-16812 to KEV catalog with federal agency patch deadline of July 30, 2026.
Business Impact
CVSS 10.0 critical vulnerability allows unauthenticated remote attackers to execute arbitrary code on VCO hosts via command injection. Successful exploitation compromises confidentiality, integrity, and availability of the orchestrator and all managed data. Attackers may pivot to VeloCloud Edge devices managed by compromised orchestrators. Federal agencies face mandatory patching deadline. Number of affected customers and attack scope unknown.
Urgency
🔴 Immediate
Recommended Actions
- Update on-premises VCO immediately to fixed versions: 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1 or later
- Block attacker IPs 8.19.75.217, 206.72.242.124, and 206.72.242.162 at perimeter firewalls and review logs for evidence of contact
- Preserve VCO web access logs, backend application logs, system logs, database logs, and file-system timestamps before remediation if compromise is suspected
- Restrict VCO web interface access to trusted administrative networks only via firewall rules or ACLs until patching is complete
- Review managed VeloCloud Edge devices for unauthorized credential changes, configuration modifications, and unexpected administrator activity if VCO compromise is confirmed
