Arista published Security Advisory 0144 on July 27, disclosing CVE-2026-16812, a maximum-severity flaw (CVSS 10.0 under both the 3.1 and 4.0 scoring standards) in on-premises deployments of VeloCloud Orchestrator, the management plane that provisions and steers traffic across an SD-WAN fabric. The flaw is an unauthenticated OS command injection: an attacker needs no credentials at all, only network access to the orchestrator’s web interface, to reach privileged internal functionality that was never meant to be exposed. Arista says the vulnerability is already being actively exploited and has shipped fixes in VCO versions 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1 and later across the affected branches.

The severity score understates why this matters operationally. An SD-WAN orchestrator is not one appliance among many; it is the single control plane that provisions, configures, and steers traffic for every branch office and edge site attached to it. Compromising the orchestrator gives an attacker leverage over the confidentiality, integrity, and availability of an entire managed fabric from one unauthenticated request, not just the box it runs on.

This is the same pattern CyberTech tracked in its earlier coverage of NetScaler and ColdFusion flaws being weaponized within hours of disclosure: perimeter and orchestration software is now targeted the same day a fix ships, sometimes before. A CVSS 10.0 disclosed alongside confirmation of active exploitation leaves defenders no real patch window, only an inventory question that needs an answer today: is VeloCloud Orchestrator reachable from outside the management network, and has it already been patched to a fixed build.

Source: Arista Networks