CVE-2026-16812 – Arista Networks VeloCloud Orchestrator On-Prem

CVSS 10 CRITICAL Zero Day – Immediate Deployment

“An internal feature exposed to the internet can quickly become an attacker's fastest path to full compromise.”

This patch addresses CVE-2026-16812, a critical vulnerability affecting Arista Networks VeloCloud Orchestrator On-Prem. The flaw allows a remote attacker to access privileged internal functionality that was intended for internal use only. Successful exploitation can impact the VCO host and compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. Hosted and Dedicated versions of VCO were patched before this advisory was released.

The CVSS score is 10.0, which is Critical severity. Active exploitation has been confirmed. The vulnerability also enables remote code execution (RCE), making this an urgent patching priority for organizations running on-premises VeloCloud Orchestrator deployments.

Key Details

Affected Product
Arista Velocloud Orchestrator
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-78
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.