Arista VeloCloud Orchestrator Zero-Day Vulnerability Exploited

www.news4hackers.com-arista-velocloud-orchestrator-zero-day-vulnerability-exploited-arista-velocloud-orchestrator-zero-day-vulnerability-exploited

Arista Networks issued patches for a critical zero-day vulnerability in VeloCloud Orchestrator, CVE-2026-16812, with active exploitation reported.

Vulnerability Overview

Arista Networks issued patches on Monday for a high-severity operating system injection flaw within the VeloCloud Orchestrator (VCO) management system, citing active exploitation in real-world scenarios as a zero-day threat.

The vulnerability, designated CVE-2026-16812, carries a maximum Common Vulnerability Scoring System (CVSS) rating of 10, indicating a critical risk level. The flaw allows remote attackers to access privileged functions designed for internal use, potentially compromising the confidentiality, integrity, and availability of the orchestrator and its managed data.

Affected Components and Patches

The affected component is the VeloCloud Orchestrator On-Prem, previously known as VeloCloud Orchestrator by Broadcom. The vulnerability was resolved in versions 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. Arista confirmed that the issue was identified externally and is currently being actively exploited. Notably, no specific configuration or authentication is required to exploit the flaw, as the VCO platform is exposed by default.

Security Team Recommendations

Security teams are advised to monitor VCO web access logs for anomalous activity, including unusual URL paths, and to inspect backend application and system logs for signs of compromise. Particular attention should be paid to requests from suspicious IP addresses, outbound HTTP/S traffic, and unauthorized privileged actions unrelated to standard administrative processes. Additionally, defenders should investigate unexpected activities such as command execution, database exports, file creation, and access to device inventory, configurations, certificates, credentials, and cryptographic materials. In the event of suspected compromise, operators are urged to retain VCO web access logs, backend application logs, system logs, database logs, and file-system timestamps before applying remediation measures.

CISA’s Role and Advisory

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) included CVE-2026-16812 in its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to apply patches within three days per Binding Operational Directive (BOD) 26-04. CISA also highlighted ongoing exploitation of CVE-2025-68686, a vulnerability linked to a patch bypass in Fortinet’s FortiOS SSL-VPN implementations. This includes previously disclosed flaws such as CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762.

Broader Security Context

Other recent developments include the exploitation of a PTC Windchill vulnerability in ransomware campaigns, a new Check Point zero-day under active attack, and a flaw in an Adobe extension with over 300 million installations enabling data theft. Additionally, a fourth SharePoint vulnerability was reported as part of a recent wave of attacks.

Conclusion

CISA’s advisory underscores the urgency of addressing critical vulnerabilities, as threat actors continue to leverage unpatched systems for malicious activities. Organizations are encouraged to prioritize remediation and implement proactive monitoring to mitigate risks associated with exploited flaws.



About Author

en_USEnglish