HackMyIP
← Back to News
2026-07-28 The Hacker News

Arista VeloCloud CVE-2026-16812 Under Active Attack: Patch Critical RCE Flaw Now

VulnerabilityThreat IntelIncident Response

A maximum-severity command injection vulnerability in on-premises Arista VeloCloud Orchestrator (VCO) is being actively exploited in the wild, prompting an urgent call for administrators to apply patches and audit their environments. Tracked as CVE-2026-16812 with a CVSS score of 10.0, the flaw resides in functionality intended for internal use only but was found to be remotely accessible, enabling unauthenticated attackers to execute arbitrary operating system commands on the VCO host. Successful exploitation could compromise the confidentiality, integrity, and availability of the orchestrator and all data it manages.

Arista confirmed that hosted and dedicated VCO instances have already been patched, but on-prem deployments remain exposed. Affected versions include VCO 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.2.4, and 7.0.x prior to 7.0.0.1. The company disclosed three IP addresses responsible for conducting the attacks and urged customers to block them: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Security teams investigating potential exposure can run a WHOIS lookup on these indicators to map out ownership and upstream infrastructure, and use a port scanner to confirm whether their VCO web interface is reachable from the internet. Arista emphasized that compromises to VCO may also grant attackers access to managed VeloCloud Edge devices, expanding the blast radius significantly.

In response, CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities (KEV) catalog, mandating that Federal Civilian Executive Branch agencies apply the fix by July 30, 2026. The agency also added a medium-severity Fortinet FortiOS SSL-VPN flaw (CVE-2025-68686, CVSS 5.3) to the catalog in the same action. For organizations that cannot update immediately, Arista recommends restricting VCO web interface access to trusted administrative networks, monitoring for connections from known malicious IPs, inspecting outbound traffic from the VCO host, and reviewing recent administrator activity. Suspected compromises should preserve VCO web access logs, backend application logs, system logs, database logs, and file-system timestamps before remediation. Credential rotation, validation of managed device state, and restoration of affected orchestrator instances from trusted sources are also advised to fully evict attackers who may have leveraged this flaw to pivot deeper into the network.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →