DIRAS TAKE
Urgent: this is listed on CISA’s Known Exploited Vulnerabilities catalog with a 2026-07-30 remediation date and the bug requires no authentication, so prioritize patching or mitigating internet-exposed VCO instances immediately.
What is CVE-2026-16812?
Remote attackers can execute operating-system commands on Arista VeloCloud Orchestrator (VCO) on‑prem, allowing full compromise of the orchestrator and managed data. CVE-2026-16812 is a command injection flaw (CWE-78) that affects multiple on‑prem VCO branches: 5.2.0 through before 5.2.3.14, 6.1.0 through before 6.1.3.4, 6.4.0 through before 6.4.2.4, and 7.0.0 through before 7.0.0.1; exploitation requires network access and no authentication or user interaction. The weakness is classified as CWE-78 (OS Command Injection).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of Arista VeloCloud Orchestrator are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 5.x | 5.2.0 – before 5.2.3.14 | 5.2.3.14 |
| 6.x | 6.1.0 – before 6.1.3.4 | 6.1.3.4 |
| 6.x | 6.4.0 – before 6.4.2.4 | 6.4.2.4 |
| 7.x | 7.0.0 – before 7.0.0.1 | 7.0.0.1 |
Is CVE-2026-16812 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-07-27, and U.S. federal agencies must remediate it by 2026-07-30.
How to fix CVE-2026-16812
- Apply vendor patches: upgrade to 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1 as appropriate.
- If you cannot patch immediately, follow Arista mitigation guidance and remove or block external access to on‑prem VCO interfaces.
- Restrict access to the orchestrator to trusted management networks and firewall off internet exposure.
- Monitor VCO logs and endpoints for suspicious activity and follow forensic guidance recommended by CISA.
Frequently asked questions
Is CVE-2026-16812 being actively exploited?
CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog on 2026-07-27, requiring federal remediation by 2026-07-30.
Which VeloCloud Orchestrator versions are affected by CVE-2026-16812?
On‑prem VeloCloud Orchestrator versions 5.2.0 through before 5.2.3.14, 6.1.0 through before 6.1.3.4, 6.4.0 through before 6.4.2.4, and 7.0.0 through before 7.0.0.1 are affected.
Is there a patch for CVE-2026-16812?
Yes; Arista published fixes—upgrade to 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1 depending on your branch.
Does CVE-2026-16812 require authentication?
No; the vulnerability can be exploited without authentication or user interaction against VeloCloud Orchestrator.
References
- nvd.nist.gov/vuln/detail/CVE-2026-16812
- cve.org/CVERecord?id=CVE-2026-16812
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16812
- arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
- All Arista CVEs on CVE Radar
- CVEs published in September 2026