VeloCloud Orchestrator CVE-2026-16812: Unauthenticated OS Command Injection Actively Exploited
1. Basic Information
- Article Title: Arista patches VeloCloud Orchestrator zero-day exploited in attacks
- Source: BleepingComputer (Primary Source: Arista Security Advisory 0144)
- Publication Date: 2026-07-27
- Original URL: https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/
- Related Sources:
- Related Entities: CVE-2026-16812, CWE-78, VeloCloud Orchestrator (VCO) On-Premises, VeloCloud Edge, CISA KEV
- Severity: Critical
-
IOCs:
8.19.75.217,206.72.242.124,206.72.242.162
2. Summary
This is a CVSS 10.0 vulnerability. It allows an unauthenticated attacker to access the Web UI of an internet-reachable on-premises VCO. The attacker can execute OS commands through internal-only functions. Active exploitation has been confirmed.
3. Attack Flow
- An attacker searches for a VCO Web interface.
- The attacker sends a crafted request without authentication to reach internal-only functions.
- The attacker executes commands on the VCO host via OS command injection.
- The attacker may access configurations, device lists, credentials, certificates, keys, and databases.
- The attacker proceeds to create files, export databases, create archives, perform outbound communications, and change management configurations.
- Inference: The attacker can abuse the authentication and configuration paths to Edge devices managed by the VCO, expanding the impact to the entire SD-WAN.
4. Attacker Position and Execution Location
- The attacker is an external host with network access to the VCO Web UI.
- The initial request targets the web layer. Commands execute on the on-premises VCO host.
- Hosted and Dedicated VCOs are already patched. VeloCloud Gateways and Edges themselves are not directly targeted by this CVE.
5. Visibility for Victims and Administrators
- There are no user interactions or failed login attempts.
- Web logs may show encoded characters, URL-like paths, internal service references, and high-frequency requests.
- The host may retain unexpected commands, files, database exports, archives, and outbound HTTP(S) traffic.
- The management console may show unexplained configuration changes or maintenance operations.
6. Success and Failure Conditions
Success Conditions
- The target runs a vulnerable on-premises version (earlier than 5.2.3.14, 6.1.3.4, 6.4.2.4, 7.0.0.1).
- The VCO Web UI is reachable from the attacker.
- WAFs, ACLs, IPS, or similar defenses do not block the exploit request.
Failure Conditions
- The patched version is applied, or the environment uses a Hosted/Dedicated version.
- The Web UI is restricted to trusted management networks.
- The requests or subsequent commands are detected and blocked.
7. What Happens Upon Success
The confidentiality, integrity, and availability of the VCO host and management data can be lost. Arista also states that Edge devices could be accessed from a compromised VCO. Because patches do not remove existing compromises, any suspicion requires rotating credentials, certificates, and keys, checking management operations, validating Edge states, and restoring or replacing the VCO from a trusted source.
8. Observable Logs
- Email: Not directly related.
- Proxy/SWG/DNS: IOC traffic targeting the VCO, and unknown outbound HTTP(S) traffic originating from the VCO.
- Endpoint/EDR: Unexpected shells, commands, files, archives, and processes on the VCO. If EDR is unavailable on the appliance, OS and file system preservation is necessary.
- Identity/IdP: No authentication is required. Track post-compromise administrator actions and the use of credentials and certificates.
- SaaS/Cloud: Hosted/Dedicated versions are patched. Audit tenant setting changes.
- Network: Abnormal requests to the Web UI, internal service references, new egress traffic from the VCO, and abnormal traffic from the VCO to Edge or management networks.
9. Attack Success Determination
| Phase | Judgment |
|---|---|
| Contact Only | Access to the Web UI from an IOC or unknown IP |
| Exploitation Attempt | Abnormal paths, encoded characters, internal service references |
| Initial Execution | Unexpected commands and processes at the same timestamp |
| Host Compromise | File creation, database access, archives, outbound communication |
| Data Theft | Matching exports with outbound transfers |
| Subsequent Compromise | Edge configuration changes, use of credentials/keys, movement to other hosts |
Do not assume success based solely on an IOC match. However, investigate immediately as an exploitation attempt because this CVE is actively exploited.
10. Investigation Playbook
- Trigger: IOC connection, abnormal web request, VCO egress traffic, unexplained management changes.
- Initial Verification: Check version, exposure scope, first abnormal time, and Web, backend, system, and database logs.
- Endpoint: Preserve command history, processes, files, database exports, archives, and timestamps.
- Authentication/Cloud: Check usage history for administrators, APIs, Edge credentials, certificates, and keys.
- Subsequent Operations: Compare differences in Edge configurations, routing, VPNs, administrators, firmware, and outbound communications.
- Containment: Restrict the Web UI to the management network, block IOCs, preserve evidence, apply patches, rotate secrets, and rebuild the VCO if necessary.
- Verdict Categories: Exposure / Attempted Exploitation / Host Compromise / Data Access / Edge Impact.
11. Defense and Detection Ideas
- Single Event: IOCs, abnormal URLs including internal service references, and newly seen egress traffic from the VCO.
- Time-Series Correlation: Abnormal web requests $\rightarrow$ VCO commands $\rightarrow$ file/database export $\rightarrow$ archive $\rightarrow$ egress traffic.
- Hunting: Unknown management changes, certificate/key access, bulk changes to Edges, and lateral movement from the VCO.
- Log Gaps: Preserve VCO Web, backend, system, and database logs along with file timestamps externally.
- Priority Actions: Apply patches, restrict management access, control egress traffic, rotate secrets, and check management configurations against a baseline.
12. Facts / Inference / Hypothesis
Facts
- CVSS 3.1 and 4.0 scores are both 10.0. No authentication or user interaction is required.
- On-premises VCOs are exposed by default, and product settings alone cannot disable this exposure.
- Arista and CISA confirmed active exploitation and released three attacker IP addresses.
- Details of the attack procedure and the identity of the attackers have not been released.
Inference
- If secrets inside the VCO are stolen, access to Edges and management APIs may persist even after patching.
Hypothesis
- Correlating web anomalies with VCO egress and database exports within a few minutes provides high-confidence detection.
13. MITRE ATT&CK Mapping
- T1190 Exploit Public-Facing Application (High)
- T1059 Command and Scripting Interpreter (High)
- T1005 Data from Local System (Medium)
- T1552 Unsecured Credentials (Medium - when credentials/keys are accessed)
- T1074 Data Staged (Medium - when archives are confirmed)
- T1041 Exfiltration Over C2 Channel (Low - when transfers are confirmed)
- T1021 Remote Services (Low - when subsequent access to Edges or other assets is confirmed)
14. Unknowns and Additional Research
- Exact HTTP requests, execution user, web shells, and additional payloads.
- Exploitation start date, number of victims, attackers, stolen data, and real-world examples of Edge compromises.
- Impact on unsupported versions.
15. Impact on SOCs and General Enterprises
For enterprises, telecommunication providers, and managed service providers (MSPs) that centrally manage domestic and remote branch offices using SD-WAN, a single VCO compromise can affect numerous Edges and branch communications. Prioritize asset inventory reviews, network segmentation for management planes, and assumption of compromise for secrets visible to the VCO, followed by immediate rotation.
16. Summary by Role
- For SOCs: Investigate web anomalies, VCO commands, databases/files, egress traffic, and Edge changes as a single timeline.
- For Administrators: Update immediately and restrict the Web UI to the management network. If compromise is suspected, do not rely solely on patches; verify keys, credentials, and Edge states.
- For Users: No user action is required. If VCO operators find anomalies, preserve evidence before restarting or deleting, and contact the SOC.
0 Comments
Log in to join the conversation.No comments yet. Be the first to share your thoughts.