• CISA KEV
  • EXPLOITED
  • PATCH AVAILABLE

CVE-2026-16812: pre-auth command injection in Arista VeloCloud Orchestrator

Remote attackers can execute operating-system commands on Arista VeloCloud Orchestrator (VCO) on‑prem, allowing full compromise of the orchestrator and managed data. CVE-2026-16812 is a command injection flaw (CWE-78) that affects multiple on‑prem VCO branches: 5.2.0 through before 5.2.3.14, 6.1.0 through before 6.1.3.4, 6.4.0 through before 6.4.2.4, and 7.0.0 through before 7.0.0.1; exploitation requires network access and no authentication or user interaction.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.01001
CWE
CWE-78
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: this is listed on CISA’s Known Exploited Vulnerabilities catalog with a 2026-07-30 remediation date and the bug requires no authentication, so prioritize patching or mitigating internet-exposed VCO instances immediately.

What is CVE-2026-16812?

Remote attackers can execute operating-system commands on Arista VeloCloud Orchestrator (VCO) on‑prem, allowing full compromise of the orchestrator and managed data. CVE-2026-16812 is a command injection flaw (CWE-78) that affects multiple on‑prem VCO branches: 5.2.0 through before 5.2.3.14, 6.1.0 through before 6.1.3.4, 6.4.0 through before 6.4.2.4, and 7.0.0 through before 7.0.0.1; exploitation requires network access and no authentication or user interaction. The weakness is classified as CWE-78 (OS Command Injection).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Arista VeloCloud Orchestrator are affected?

BRANCHAFFECTEDFIXED
5.x5.2.0 – before 5.2.3.145.2.3.14
6.x6.1.0 – before 6.1.3.46.1.3.4
6.x6.4.0 – before 6.4.2.46.4.2.4
7.x7.0.0 – before 7.0.0.17.0.0.1

Is CVE-2026-16812 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-07-27, and U.S. federal agencies must remediate it by 2026-07-30.

How to fix CVE-2026-16812

  1. Apply vendor patches: upgrade to 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1 as appropriate.
  2. If you cannot patch immediately, follow Arista mitigation guidance and remove or block external access to on‑prem VCO interfaces.
  3. Restrict access to the orchestrator to trusted management networks and firewall off internet exposure.
  4. Monitor VCO logs and endpoints for suspicious activity and follow forensic guidance recommended by CISA.

Frequently asked questions

Is CVE-2026-16812 being actively exploited?

CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog on 2026-07-27, requiring federal remediation by 2026-07-30.

Which VeloCloud Orchestrator versions are affected by CVE-2026-16812?

On‑prem VeloCloud Orchestrator versions 5.2.0 through before 5.2.3.14, 6.1.0 through before 6.1.3.4, 6.4.0 through before 6.4.2.4, and 7.0.0 through before 7.0.0.1 are affected.

Is there a patch for CVE-2026-16812?

Yes; Arista published fixes—upgrade to 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1 depending on your branch.

Does CVE-2026-16812 require authentication?

No; the vulnerability can be exploited without authentication or user interaction against VeloCloud Orchestrator.

References