Back to Blog
CVE-2026-16812: Arista VeloCloud Orchestrator — Remote Code Execution Risk (July 2026)
vulnerabilities

CVE-2026-16812: Arista VeloCloud Orchestrator — Remote Code Execution Risk (July 2026)

breachwire TeamJul 29, 20262 min read

CVE-2026-16812 — Arista VeloCloud Orchestrator

CVE-2026-16812 is a critical command injection vulnerability in on-premises Arista VeloCloud Orchestrator. Attackers are actively exploiting this flaw to achieve remote code execution, threatening the confidentiality, integrity, and availability of orchestrator deployments. The U.S. CISA has added this CVE to its Known Exploited Vulnerabilities catalog, requiring patching by July 30, 2026.

Attack Vector

Remote, unauthenticated attackers exploit CVE-2026-16812 by sending crafted requests to vulnerable VeloCloud Orchestrator instances. Successful exploitation enables arbitrary command execution with orchestrator privileges, potentially allowing attackers to manipulate managed network devices and disrupt operations. Indicators of compromise include connections from IPs 8.19.75.217, 206.72.242.124, and 206.72.242.162. Attackers leverage this access to pivot further into enterprise networks.

Who Is at Risk

All organizations running on-premises versions of Arista VeloCloud Orchestrator are at immediate risk. Arista Networks customers with unpatched orchestrators are confirmed affected. Cloud-hosted versions are not impacted. North American deployments are currently targeted, but global exposure is likely.

Patch & Mitigate

  • Patch: Apply Arista’s security update for VeloCloud Orchestrator immediately; patch deadline is July 30, 2026 per CISA.
  • Workaround: Restrict network access to the orchestrator management interface and enforce strict firewall rules until patching is complete.
  • Detect: Monitor logs for suspicious requests and outbound connections to the IOCs: 8.19.75.217, 206.72.242.124, 206.72.242.162. Review for unauthorized command execution or configuration changes.

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers exploit a remote entry point to gain access to the orchestrator.
  • TA0005 — Defense Evasion: Malicious commands may disable logging or alter configurations to avoid detection.
  • TA0007 — Discovery: Post-exploitation, attackers enumerate internal network resources and managed devices.

Source: https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: