Jessica Entwistle
July 28 2026
CISA and multiple security vendors report that a maximum-severity vulnerability in Arista VeloCloud Orchestrator on-premises deployments is being actively exploited in the wild. The flaw, tracked as CVE-2026-16812 with a CVSS score of 10.0, is an operating system command injection vulnerability that allows attackers to execute arbitrary code on affected systems. The vulnerability affects the on-premises version of VeloCloud Orchestrator, a platform used to manage SD-WAN infrastructure. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalogue, indicating confirmed exploitation activity. Arista has released patches and organisations running on-premises VeloCloud Orchestrator are advised to apply updates immediately.
For UK organisations using SD-WAN infrastructure, particularly those with on-premises VeloCloud Orchestrator deployments, this represents an immediate and serious risk. SD-WAN platforms sit at the centre of network connectivity, managing traffic routing, security policies and access controls across distributed sites. A command injection vulnerability with a severity score of 10.0 means attackers can gain full control of the orchestrator, potentially allowing them to intercept traffic, modify routing policies, access connected networks or use the compromised platform as a pivot point into the wider environment. The fact that active exploitation is already occurring means this is not a theoretical risk—it is happening now, and unpatched systems are exposed. The vulnerability also highlights the broader challenge of securing network infrastructure that is often deployed in branch offices, remote sites or managed service environments where visibility and patching discipline may be less consistent than in core data centres.
UK businesses running Arista VeloCloud Orchestrator on-premises should treat patching CVE-2026-16812 as an immediate priority and review whether the platform is appropriately segmented, monitored and protected. Consider whether you have visibility into access logs, configuration changes and unusual activity on the orchestrator, and whether incident response plans account for compromise of core network infrastructure. Review whether SD-WAN platforms are deployed with least privilege access controls, whether administrative interfaces are exposed to the internet, and whether multi-factor authentication is enforced for management access. Assess whether your organisation has an accurate inventory of network infrastructure, including SD-WAN controllers, edge devices and orchestration platforms, and whether vulnerability management processes can identify and prioritise patching for these systems. Finally, consider whether network segmentation and monitoring controls would detect or limit the impact of a compromised SD-WAN platform, and whether backup configurations and recovery processes are in place to restore service if the orchestrator is compromised.
Source: CISA Advisories