Arista VeloCloud Orchestrator Hits CISA KEV
CISA adds CVE-2026-16812 to KEV: CVSS 10.0 OS command injection in Arista VeloCloud Orchestrator On-Prem. Remote exploitation confirmed. Patch immediately.
Arista VeloCloud Orchestrator On-Prem landed on CISA’s Known Exploited Vulnerabilities list today. CVE-2026-16812: OS command injection, CVSS 10.0. A remote attacker can reach privileged internal functionality and fully compromise the orchestrator host.
VeloCloud Orchestrator is the management and control plane for Arista’s SD-WAN product line. Compromising the VCO means compromising policy enforcement, network visibility, and traffic routing decisions across every site in the SD-WAN fabric. This is not a peripheral component.
CISA’s KEV addition confirms active exploitation in the wild — not theoretical, not proof-of-concept only.
What’s vulnerable
OS command injection in VeloCloud Orchestrator On-Prem. Per CISA’s KEV catalog and Arista’s SA-0144: a remote attacker can access privileged internal functionality and impact the VCO host. Successful exploitation compromises confidentiality, integrity, and availability of the orchestrator and all data managed through it.
For full technical details, affected version ranges, and fixed builds: consult SA-0144 and the NVD record directly — both will be updated as more information is confirmed.
What to do
- Pull up SA-0144 now. Arista’s advisory is the authoritative source on patched versions. Identify your exact VCO build, map it to the fix, and start the upgrade path.
- Restrict orchestrator access at the network level while you patch. If the VCO is reachable from untrusted segments or the public internet, close that off immediately. Network controls are faster to apply than a full software upgrade and close the window while you work the patch.
- Inventory every VCO in your environment. Distributed SD-WAN deployments sometimes have multiple orchestrator instances — test, staging, and regional. All of them need the same treatment.
- Federal agencies: BOD 26-04 puts you on a mandated remediation deadline for KEV additions. The implementation guidance covers what forensic triage looks like if you need to assess prior exposure before patching.
Priority call: this goes to the top of the queue. CVSS 10.0, active exploitation confirmed. The KEV tracker has the full catalog if you’re working a broader remediation list.
- [ CRITICAL ] CVE-2026-16812 Arista VeloCloud Orchestrator OS Command Injection
Found this useful? Share it.