Arista Networks has urgently released patches to fix a critical OS injection vulnerability in its VeloCloud Orchestrator (VCO) platform. The vulnerability, identified as CVE-2026-16812, has been actively exploited in the wild and holds a maximum CVSS score of 10. This flaw allows remote attackers to gain unauthorized access to privileged functions, threatening the confidentiality, integrity, and availability of the system and its managed data. The vulnerability specifically affects the VeloCloud Orchestrator On-Prem version, formerly known as VeloCloud Orchestrator by Broadcom. Arista has addressed this issue in VCO versions 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1.

The attack does not require special configuration or authentication, making VCO vulnerable by default to anyone with network access to the web interface. As a result, Arista strongly advises system defenders to review their VCO web access logs for any unexpected activity or unusual URL-like path components. Additionally, backend application logs and system logs should be examined for activities such as requests from suspicious IPs, unexpected outbound HTTP/S traffic, and privileged actions not linked to standard administrative workflows.

If there is any suspicion of compromise, operators are encouraged to preserve all relevant logs and timestamps before proceeding with remediation. The US Cybersecurity and Infrastructure Security Agency (CISA) has also added CVE-2026-16812 to its list of Known Exploited Vulnerabilities, urging federal agencies to patch it within three days, as required by binding operational directive BOD 26-04. This incident underscores the urgent need for organizations using VeloCloud Orchestrator On-Prem to implement the available patches immediately to protect their systems and data.