A critical vulnerability in Arista VeloCloud Orchestrator is currently being actively exploited. CISA has added the flaw, rated at the maximum severity of 10.0, to its KEV list.
A critical security vulnerability in on-premises installations of Arista VeloCloud Orchestrator (VCO) is currently being actively exploited. The vulnerability is tracked under the identifier CVE-2026-16812 and reaches the maximum CVSS severity of 10.0. It is an operating system command injection that allows the execution of arbitrary program code without prior authentication. Arista Networks stated on the matter:
“VeloCloud Orchestrator (VCO) On-Prem has a security issue that can allow a remote attacker to access privileged internal functionality and compromise the VCO host. Successful exploitation can compromise the confidentiality, integrity, and availability of the Orchestrator and the data it manages. This functionality was intended for internal use only and should not be accessible remotely.”
Arista Networks
The US cybersecurity agency CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog and is requiring civilian federal agencies to remediate it by July 30, 2026.
Affected versions and emergency measures at Arista VeloCloud
The security vulnerability affects on-premises variants exclusively. Hosted and Dedicated instances were updated in advance by the manufacturer. The following software versions are affected:
- VCO 5.2.x prior to version 5.2.3.14
- VCO 6.1.x prior to version 6.1.3.4
- VCO 6.4.x prior to version 6.4.2.4
- VCO 7.0.x prior to version 7.0.0.1
To check networks, Arista has published three IP addresses as indicators of attack: 8.19.75.217, 206.72.242.124, and 206.72.242.162. If patches cannot be applied immediately, restricting access to the management interface to trusted networks is recommended. Regarding downstream systems, the manufacturer warned: “Compromises of the VCO platform can also give attackers access to the VeloCloud Edge devices.”
Further KEV catalog additions concerning Fortinet and Fastjson
In addition to the Arista flaw, CISA has added further actively exploited vulnerabilities to its catalog. These include CVE-2025-68686 (CVSS 5.3) in Fortinet FortiOS SSL-VPN, a vulnerability involving disclosure of confidential information that allows bypassing previous protective measures relating to existing file system permissions. A remediation deadline of August 10, 2026 applies here.
In addition, the unpatched flaw CVE-2026-16723 (CVSS 9.0) in Alibaba’s Fastjson library is being exploited. Developers using the affected versions 1.2.68 through 1.2.83 are advised to enable SafeMode or switch to unaffected versions.
(red)