CISA adds CVE-2026-16812 to KEV catalog
CISA added a critical, actively exploited flaw in Arista VeloCloud Orchestrator on-premises to its KEV catalog, with an urgent patch due.
CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog after finding active exploitation. The flaw affects Arista VeloCloud Orchestrator on-premises, carries a CVSS 10.0 score, and must be patched by July 30, 2026 for U.S. federal civilian agencies.
CISA has added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog after finding evidence of active exploitation. The flaw affects Arista VeloCloud Orchestrator only in on-premises deployments, and it is classified as an operating system command injection vulnerability with a CVSS severity score of 10.0.
Technical scope
Available coverage indicates that the vulnerable on-premises versions of VeloCloud Orchestrator are VCO 5.2.x earlier than 5.2.3.14, VCO 6.1.x earlier than 6.1.3.4, VCO 6.4.x earlier than 6.4.2.4, and VCO 7.0.x earlier than 7.0.0.1. The fixed binaries are 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1, and later.
BleepingComputer says exploitation of this vulnerability allows remote attackers to access privileged functionality that should be limited to internal use and not exposed remotely. That increases the potential impact on the orchestration platform and on the SD-WAN network it manages.
MyTech-Blog says Arista published its security advisory for CVE-2026-16812 on July 27, 2026, and that CISA added it to the KEV catalog the same day, with a base score of 10.0 under both CVSSv3.1 and CVSSv4.0.
What is affected and what is not
Available coverage agrees that only VeloCloud Orchestrator on-premises deployments are vulnerable. The Hosted and Dedicated versions, along with VeloCloud Gateway and VeloCloud Edge, are not affected and were patched preventively before public disclosure.
Arista had already fixed the hosted and dedicated versions of VeloCloud Orchestrator before the advisory was made public, according to available information. Ayinedjimi Consultants also cites Arista Security Advisory 0144 as a reference for the target patch versions and update instructions.
Deadline and response
The deadline listed for U.S. federal civilian executive agencies is July 30, 2026. MyTech-Blog notes that inclusion in KEV implies evidence of real-world exploitation and leaves just three days between the advisory release and the CISA deadline.
There is no configuration-based mitigation that closes the attack vector. MyTech-Blog says the response is limited to updating to fixed versions and applying network-level restrictions to the web interface.
Ayinedjimi Consultants warns that any unpatched VeloCloud Orchestrator on-premises instance should be treated as potentially compromised, given the active exploitation and the CVSS 10.0 severity, and recommends treating the update as immediate and high priority.
Feedly CVE Tracker, meanwhile, reports no evidence of a public exploit or proof of concept for CVE-2026-16812, even though active exploitation in the wild has already been confirmed.
Sources
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flawthehackernews.com· The Hacker News
- CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator explotada activamenteciberplaneta.org· CiberPlaneta
- CVE-2026-16812 : Arista VeloCloud Orchestrator CVSS 10.0 ajouté au KEVayinedjimi-consultants.fr· Ayine Djimi Consultants
- CVE-2026-16812 - Exploits & Severityfeedly.com· Feedly
- Arista patches VeloCloud Orchestrator zero-day exploited in attacksbleepingcomputer.com· BleepingComputer
- VeloCloud Orchestrator の脆弱性|CVE-2026-16812 のリスクmytech-blog.com· MyTech-Blog



