Security Patch & Exposure

Arista Patches Critical VeloCloud Orchestrator Zero-Day Exploited in the Wild

Arista Networks released fixes for CVE-2026-16812, a critical OS command injection flaw in on-premises VeloCloud Orchestrator deployments that has been exploited as a zero-day.

Arista Networks has released patches for a critical vulnerability in VeloCloud Orchestrator, warning that the flaw has been exploited in the wild as a zero-day.

The vulnerability is tracked as CVE-2026-16812 and has a CVSS score of 10. According to the referenced report, the issue is an OS command injection flaw that can be exploited remotely to access privileged internal functionality.

Arista said successful exploitation may affect the confidentiality, integrity, and availability of the orchestrator and the data it manages. The affected product is VeloCloud Orchestrator On-Prem, formerly VeloCloud Orchestrator by Broadcom.

The company addressed the issue in VCO versions 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1.

The report states that exploitation does not require special configuration or authentication. Network access to the VCO web interface is required, and VCO tenant or operator credentials are not required for exposure.

Arista advised defenders to review VCO web access logs for unexpected activity and unusual URL-like path components. The company also recommended reviewing backend application logs and system logs for follow-up activity, including requests from malicious IP addresses, outbound HTTP or HTTPS activity, and privileged actions not associated with administrative workflows.

Defenders should also look for unexpected activity involving command execution, database exports, file creation, and access to device inventory, configurations, certificates, credentials, and key material.

If compromise is suspected, Arista recommended preserving VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible.

The report also states that CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and urged federal agencies to patch within three days under BOD 26-04.

For organizations running affected on-premises deployments, the priority is to identify exposed VCO instances, confirm version status, preserve relevant logs where needed, and apply fixed versions through approved change processes.

FAQ operasional

Pertanyaan lanjutan untuk tim IT.

Apa langkah pertama setelah membaca Arista Patches Critical VeloCloud Orchestrator Zero-Day Exploited in the Wild?

Mulai dari inventaris sistem yang terdampak, owner operasional, kontrol yang sudah berjalan, dan bukti terakhir seperti patch status, log, atau hasil restore test.

Tim mana yang sebaiknya dilibatkan?

Libatkan IT manager, security atau infrastructure owner, application owner, dan pihak operasional yang memahami dampak bisnis jika sistem harus dipatch, diisolasi, atau dipulihkan.

Kapan perlu eskalasi ke assessment myBATICloud?

Eskalasi jika sistem bersifat kritikal, terekspos internet, akses admin belum rapi, backup belum pernah diuji, atau tim membutuhkan prioritas teknis yang bisa dieksekusi dalam 30 hari.