INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Arista VeloCloud Orchestrator Exploit Vulnerability Found
| 2026-07-28 04:43 CRITICAL HIGHExecutive Summary AI-generated
The vulnerability, CVE-2026-16812, has been added to the Known Exploited Vulnerabilities (KEV) catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). This information disclosure vulnerability affects multiple versions of Fortinet's FortiOS operating system, exposing privileged internal functionality that was intended for trusted components only. The flaw allows specially crafted HTTP requests to bypass symbolic link protection, potentially compromising confidentiality, integrity, and availability of both the orchestrator and network data it manages. Organizations are advised to block affected IP addresses and check logs for signs of compromise as soon as possible.
Technical Mitigations AI-generated
* Implement a secure patching strategy for FortiOS and VeloCloud Orchestrator to prevent the persistence of malicious symbolic links, including:
+ Regularly updating and patching operating systems and applications
+ Using secure configuration options and monitoring system logs for signs of compromise
+ Limiting access to sensitive areas of the network and implementing role-based access control (RBAC)
* Implement a robust security posture by:
+ Conducting regular vulnerability assessments and penetration testing
+ Establishing incident response plans and procedures
+ Providing ongoing training and awareness programs for employees
* Monitor system logs, application performance, and user activity to detect signs of compromise or exploitation of the Arista VeloCloud Orchestrator command injection flaw.
* Consider implementing a web application firewall (WAF) or intrusion detection/prevention system (IDPS) to block suspicious traffic patterns and prevent attacks.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-68686CVE-2025-68686
CVE-2026-16812CVE-2026-16812
CVE-2026-16723CVE-2026-16723
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
July 20, 2026
Threat actors exploited the Arista VeloCloud Orchestrator Command Injection flaw.
Jul 28, 2026
The attackers exploited a command injection flaw in Arista VeloCloud Orchestrator (VCO) to gain unauthorized access.
Click on any entity below to view its context and source!
infrastructure
5.2
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
infrastructure
5.2.3
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
infrastructure
6.1
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
infrastructure
6.1.3
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
infrastructure
6.4
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
infrastructure
6.4.2
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
infrastructure
7.0
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
infrastructure
7.0.0
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
organisation
VCO 5.2.x
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
organisation
VCO 6.4.x
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
organisation
IP
As indicators of compromise (IoCs), the company shared a set of three IP addresses that it said were responsible for "conducting the attacks," urging customers to block them and review the logs to determine if they are present -
8.19.75.217
206.72.242.124
206.72.242.162
"If compromise is suspected, operators should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible," it added.
organisation
VCO
"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host," Arista
said
in a Monday advisory.
organisation
the VeloCloud Edge
"Compromises to the VCO platform may allow attackers access to the VeloCloud Edge devices as well," Arista said.
organisation
Arista
"Compromises to the VCO platform may allow attackers access to the VeloCloud Edge devices as well," Arista said.
2026/07/28
Arista VeloCloud Orchestrator (VCO) and Fortinet FortiOS vulnerabilities were exploited in the wild.
Click on any entity below to view its context and source!
organisation
Unauthorized Actor Vulnerability
Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
CVE-2026-16812
(CVSS score of 10.0)
organisation
VCO
The vulnerability
CVE-2026-16812
affects the on-premises VMware VeloCloud Orchestrator (VCO) and exposes privileged internal functionality that was intended to be accessible only by trusted internal components.
VeloCloud Orchestrator, also known as VCO, is a centralized management platform used to configure, monitor, and manage VeloCloud SD-WAN deployments and associated edge devices.
organisation
CVE-2026
The U.S. Cybersecurity and Infrastructure Security Agency has also added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog, confirming that the flaw is being used in attacks.
organisation
Known Exploited
The U.S. Cybersecurity and Infrastructure Security Agency has also added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog, confirming that the flaw is being used in attacks.
infrastructure
5.2
The following VeloCloud Orchestrator on-premises versions are affected:
VCO 5.2.x releases before 5.2.3.14
VCO 6.1.x releases before 6.1.3.4
VCO 6.4.x releases before 6.4.2.4
VCO 7.0.x releases before 7.0.0.1
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected.
infrastructure
5.2.3
The following VeloCloud Orchestrator on-premises versions are affected:
VCO 5.2.x releases before 5.2.3.14
VCO 6.1.x releases before 6.1.3.4
VCO 6.4.x releases before 6.4.2.4
VCO 7.0.x releases before 7.0.0.1
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected.
The company says the flaw is fixed in VCO versions 5.2.3.14, 6.1.3.4, and 6.4.2.4 and later.
infrastructure
6.1
The following VeloCloud Orchestrator on-premises versions are affected:
VCO 5.2.x releases before 5.2.3.14
VCO 6.1.x releases before 6.1.3.4
VCO 6.4.x releases before 6.4.2.4
VCO 7.0.x releases before 7.0.0.1
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected.
infrastructure
6.1.3
The following VeloCloud Orchestrator on-premises versions are affected:
VCO 5.2.x releases before 5.2.3.14
VCO 6.1.x releases before 6.1.3.4
VCO 6.4.x releases before 6.4.2.4
VCO 7.0.x releases before 7.0.0.1
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected.
The company says the flaw is fixed in VCO versions 5.2.3.14, 6.1.3.4, and 6.4.2.4 and later.
infrastructure
6.4
The following VeloCloud Orchestrator on-premises versions are affected:
VCO 5.2.x releases before 5.2.3.14
VCO 6.1.x releases before 6.1.3.4
VCO 6.4.x releases before 6.4.2.4
VCO 7.0.x releases before 7.0.0.1
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected.
infrastructure
6.4.2
The following VeloCloud Orchestrator on-premises versions are affected:
VCO 5.2.x releases before 5.2.3.14
VCO 6.1.x releases before 6.1.3.4
VCO 6.4.x releases before 6.4.2.4
VCO 7.0.x releases before 7.0.0.1
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected.
The company says the flaw is fixed in VCO versions 5.2.3.14, 6.1.3.4, and 6.4.2.4 and later.
infrastructure
7.0
The following VeloCloud Orchestrator on-premises versions are affected:
VCO 5.2.x releases before 5.2.3.14
VCO 6.1.x releases before 6.1.3.4
VCO 6.4.x releases before 6.4.2.4
VCO 7.0.x releases before 7.0.0.1
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected.
infrastructure
7.0.0
The following VeloCloud Orchestrator on-premises versions are affected:
VCO 5.2.x releases before 5.2.3.14
VCO 6.1.x releases before 6.1.3.4
VCO 6.4.x releases before 6.4.2.4
VCO 7.0.x releases before 7.0.0.1
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected.
The affected software list also indicates that VCO 7.0.0.1 and later releases are not vulnerable.
organisation
VeloCloud Orchestrator Hosted
The following VeloCloud Orchestrator on-premises versions are affected:
VCO 5.2.x releases before 5.2.3.14
VCO 6.1.x releases before 6.1.3.4
VCO 6.4.x releases before 6.4.2.4
VCO 7.0.x releases before 7.0.0.1
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected.
organisation
IP
The company also published three IP addresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to block them and check logs for signs of compromise.
Arista shared three IP addresses that were seen exploiting the vulnerability:
8.19.75.217
206.72.242.124
206.72.242.162
Administrators are advised to block these IP addresses and review their logs for previous connections.
organisation
CVSS
Below are the flaws added to the KeV catalog:
CVE-2025-68686
(CVSS score of 5.3)
organisation
CVE-2025
Below are the flaws added to the KeV catalog:
CVE-2025-68686
(CVSS score of 5.3)
organisation
VeloCloud Orchestrator Command Injection Flaw
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw.
organisation
VeloCloud Orchestrator
VeloCloud Orchestrator, also known as VCO, is a centralized management platform used to configure, monitor, and manage VeloCloud SD-WAN deployments and associated edge devices.
organisation
Arista
Arista said the vulnerability was discovered externally and is being actively exploited, but did not disclose when it was reported or how many customers may have been affected.
According to an Arista security advisory published Monday, the vulnerability allows remote attackers to access privileged functionality that was intended only for internal use and should not be remotely accessible.
organisation
Fortinet
Once the system has already been compromised, specially crafted HTTP requests can be used to bypass the symbolic link protection introduced by Fortinet, potentially exposing sensitive information that should no longer be accessible.
organisation
SD-WAN
Successful exploitation could compromise the confidentiality, integrity, and availability of both the orchestrator and the network data it manages, enabling attackers to access sensitive information, modify configurations, or disrupt SD-WAN management operations.
organisation
VMware
VMware has confirmed that the flaw is actively exploited in the wild.
organisation
Hosted
The Hosted and Dedicated VCO offerings were patched before public disclosure, while organizations running on-premises deployments should apply the available security updates as soon as possible.
organisation
BleepingComputer
BleepingComputer has contacted the company with these questions.
organisation
VeloCloud Edge
VeloCloud Gateway and VeloCloud Edge products are also not vulnerable to the flaw.
organisation
the Arista Technical Assistance Center
Customers running unsupported release trains are advised to contact the Arista Technical Assistance Center to discuss available upgrade options.
organisation
Unexpected
Organizations should review VCO logs for signs of exploitation, including:
Unusual web requests containing encoded characters, URL-like path components, references to local or internal services, or abnormally high request rates
Connections from known malicious IP addresses
Unexpected outbound HTTP or HTTPS traffic from the VCO host
Unauthorized configuration changes or privileged maintenance activity
Unexpected command execution, file creation, database exports, or archive files
Suspicious access to VCO databases, configuration data, device inventories, credentials, certificates, or cryptographic keys
If compromise is suspected, organizations should preserve all logs and filesystem timestamps before remediation.
organisation
Suspicious
Organizations should review VCO logs for signs of exploitation, including:
Unusual web requests containing encoded characters, URL-like path components, references to local or internal services, or abnormally high request rates
Connections from known malicious IP addresses
Unexpected outbound HTTP or HTTPS traffic from the VCO host
Unauthorized configuration changes or privileged maintenance activity
Unexpected command execution, file creation, database exports, or archive files
Suspicious access to VCO databases, configuration data, device inventories, credentials, certificates, or cryptographic keys
If compromise is suspected, organizations should preserve all logs and filesystem timestamps before remediation.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
July 30, 2026
Threat actors exploited a command injection flaw in Fortinet's FortiOS SSL-VPN to bypass the patch for CVE-2026-16812.
Click on any entity below to view its context and source!
attribution
Known Exploited
"
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the flaw to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patch by July 30, 2026.
tactic
T1588.006 - Vulnerabilities
"
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the flaw to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patch by July 30, 2026.
attribution
KEV
"
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the flaw to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patch by July 30, 2026.
News of active exploitation of CVE-2026-16812 arrives as the agency also added a medium-severity security vulnerability impacting Fortinet FortiOS SSL-VPN (CVE-2025-68686, CVSS score: 5.3) to the KEV catalog, citing evidence of active exploitation.
attribution
Federal Civilian Executive Branch
"
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the flaw to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patch by July 30, 2026.
attribution
FCEB
"
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the flaw to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patch by July 30, 2026.
organisation
CVE-2026
News of active exploitation of CVE-2026-16812 arrives as the agency also added a medium-severity security vulnerability impacting Fortinet FortiOS SSL-VPN (CVE-2025-68686, CVSS score: 5.3) to the KEV catalog, citing evidence of active exploitation.
organisation
Fortinet FortiOS SSL-VPN
News of active exploitation of CVE-2026-16812 arrives as the agency also added a medium-severity security vulnerability impacting Fortinet FortiOS SSL-VPN (CVE-2025-68686, CVSS score: 5.3) to the KEV catalog, citing evidence of active exploitation.
organisation
CVSS
News of active exploitation of CVE-2026-16812 arrives as the agency also added a medium-severity security vulnerability impacting Fortinet FortiOS SSL-VPN (CVE-2025-68686, CVSS score: 5.3) to the KEV catalog, citing evidence of active exploitation.
organisation
Fortinet
The shortcoming was patched by Fortinet earlier this February.
organisation
FortiOS SSL-VPN
"An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiOS SSL-VPN may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests," Fortinet
said
in an alert at the time.
organisation
Fortinet FortiOS
Fortinet FortiOS
Thursday, July 30, 2026
Threat actors exploited a command injection flaw in the Arista VeloCloud Orchestrator to gain unauthorized access.
Click on any entity below to view its context and source!
attribution
IP
CISA has ordered U.S. federal civilian executive branch agencies to mitigate the vulnerability by Thursday, July 30, 2026, as required by Binding Operational Directive 22-01.
Indicators of compromise
While patches are being deployed, administrators should restrict access to the VCO web interface to administrative networks, monitor for connections from known malicious IP addresses, and review recent administrator activity for unusual changes.
August 10, 2026
Developers using versions 1.2.68 through 1.2.83 of Alibaba's Fastjson library are urged to update due to a command injection flaw that could allow remote code execution.
Click on any entity below to view its context and source!
infrastructure
1.2.68
Developers using versions 1.2.68 through 1.2.83 are urged to enable SafeMode or switch to a non-impacted build as soon as possible.
infrastructure
1.2.83
Developers using versions 1.2.68 through 1.2.83 are urged to enable SafeMode or switch to a non-impacted build as soon as possible.
Tactical Metrics
Metrics
infrastructure
5.2
Software Version
Click for context!
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
The following VeloCloud Orchestrator on-premises versions are affected:
VCO 5.2.x releases before 5.2.3.14
VCO 6.1.x releases before 6.1.3.4
VCO 6.4.x releases before 6.4.2.4
VCO 7.0.x releases before 7.0.0.1
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected.
Metrics
infrastructure
5.2.3
Software Version
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
The following VeloCloud Orchestrator on-premises versions are affected:
VCO 5.2.x releases before 5.2.3.14
VCO 6.1.x releases before 6.1.3.4
VCO 6.4.x releases before 6.4.2.4
VCO 7.0.x releases before 7.0.0.1
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected.
The company says the flaw is fixed in VCO versions 5.2.3.14, 6.1.3.4, and 6.4.2.4 and later.
Metrics
infrastructure
6.1
Software Version
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
The following VeloCloud Orchestrator on-premises versions are affected:
VCO 5.2.x releases before 5.2.3.14
VCO 6.1.x releases before 6.1.3.4
VCO 6.4.x releases before 6.4.2.4
VCO 7.0.x releases before 7.0.0.1
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected.
Metrics
infrastructure
6.1.3
Software Version
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
The following VeloCloud Orchestrator on-premises versions are affected:
VCO 5.2.x releases before 5.2.3.14
VCO 6.1.x releases before 6.1.3.4
VCO 6.4.x releases before 6.4.2.4
VCO 7.0.x releases before 7.0.0.1
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected.
The company says the flaw is fixed in VCO versions 5.2.3.14, 6.1.3.4, and 6.4.2.4 and later.
Metrics
infrastructure
6.4
Software Version
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
The following VeloCloud Orchestrator on-premises versions are affected:
VCO 5.2.x releases before 5.2.3.14
VCO 6.1.x releases before 6.1.3.4
VCO 6.4.x releases before 6.4.2.4
VCO 7.0.x releases before 7.0.0.1
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected.
Metrics
infrastructure
6.4.2
Software Version
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
The following VeloCloud Orchestrator on-premises versions are affected:
VCO 5.2.x releases before 5.2.3.14
VCO 6.1.x releases before 6.1.3.4
VCO 6.4.x releases before 6.4.2.4
VCO 7.0.x releases before 7.0.0.1
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected.
The company says the flaw is fixed in VCO versions 5.2.3.14, 6.1.3.4, and 6.4.2.4 and later.
Metrics
infrastructure
7.0
Software Version
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
The following VeloCloud Orchestrator on-premises versions are affected:
VCO 5.2.x releases before 5.2.3.14
VCO 6.1.x releases before 6.1.3.4
VCO 6.4.x releases before 6.4.2.4
VCO 7.0.x releases before 7.0.0.1
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected.
Metrics
infrastructure
7.0.0
Software Version
The following versions are affected -
VCO 5.2.x releases prior to 5.2.3.14
VCO 6.1.x releases prior to 6.1.3.4
VCO 6.4.x releases prior to 6.4.2.4
VCO 7.0.x releases prior to 7.0.0.1
Arista acknowledged that the vulnerability was externally discovered and known to be actively exploited, but did not reveal when it was disclosed and how many customers may have been potentially impacted as part of malicious cyber activity weaponizing the bug.
The following VeloCloud Orchestrator on-premises versions are affected:
VCO 5.2.x releases before 5.2.3.14
VCO 6.1.x releases before 6.1.3.4
VCO 6.4.x releases before 6.4.2.4
VCO 7.0.x releases before 7.0.0.1
VeloCloud Orchestrator Hosted and Dedicated deployments were patched before the advisory was published and are not affected.
The affected software list also indicates that VCO 7.0.0.1 and later releases are not vulnerable.
Metrics
infrastructure
1.2.68
Software Version
Developers using versions 1.2.68 through 1.2.83 are urged to enable SafeMode or switch to a non-impacted build as soon as possible.
Metrics
infrastructure
1.2.83
Software Version
Developers using versions 1.2.68 through 1.2.83 are urged to enable SafeMode or switch to a non-impacted build as soon as possible.
Intelligence Sources
BleepingComputer
2026-07-27
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
BleepingComputer
Security Affairs
2026-07-28
The Hacker News
2026-07-28
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-28T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
29x
organisation
Identified Entity
VCO 5.2.x
entity
12x
attribution
Attributing Entity
Vulnerability / Threat Intelligence
authority
10x
infrastructure
Software Version
5.2
version
9x
timeline
Temporal Reference
Jul 28, 2026
date
3x
vulnerability
Exploited CVE
CVE-2026-16812
cve
2x
general metric
Score
5
score
2x
vulnerability
CVSS Score
5
score
2x
general metric
%
54
%
Contextual Telemetry
Context Block
5 METRICS
tactic
Cyber Operation Type
Remote Code Execution
tactic
general metric
Jul
28
jul
target region
Target Country
United States
country
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Cve-2026
16,812
cve-2026
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.