Knox CVE Database
/
CVE-2026-16812
Critical
10.0

CVE-2026-16812: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Added to the CISA KEV catalog:
July 27, 2026

Overview

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

This functionality was intended to be for internal use only and is not intended to be remotely accessible.

Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out.

This issue was discovered externally and is known to be actively exploited.

Vulnerability details

Affected vendor
Arista
Affected product
VeloCloud Orchestrator
Weakness type (CWE)
CWE-78

VeloCloud Orchestrator (VCO) On-Prem exposes an internal privileged functionality endpoint to the network that was designed for internal use only. Because the endpoint fails to sanitize attacker-supplied input before passing it to OS-level command execution (CWE-78), shell metacharacters or injected command strings in the request are interpreted and executed by the host operating system. No authentication is required to reach the endpoint, and the flaw is confirmed as actively exploited in the wild.


An attacker with network access to the VCO management interface sends crafted requests containing OS command injection payloads to the exposed internal endpoint. No credentials or user interaction are needed. Successful exploitation yields arbitrary OS command execution on the VCO host, resulting in full compromise of confidentiality, integrity, and availability of the orchestrator and all SD-WAN configuration and policy data it manages. Only on-prem deployments running affected versions are exposed; hosted and dedicated VCO instances were patched before public disclosure.

Severity and impact

10.0
Critical
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review VCO host OS-level process audit logs (auditd or equivalent) for shell processes spawned by the orchestrator service process, particularly those with parent-child relationships not present in a known-good baseline.
  • Inspect web or application access logs for requests to internal API paths that originate from external or untrusted source addresses, especially those containing shell metacharacters (semicolons, pipes, backticks, dollar signs) in parameter values.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 30, 2026

Additional hardening

  • Restrict network access to the VCO management interface using firewall rules or ACLs, permitting only trusted administrative source addresses.
  • Place the VCO management plane on an isolated network segment, preventing direct internet exposure of the orchestrator interface.
  • Conduct forensic triage per CISA BOD 26-04 requirements before patching if active exploitation is suspected on the host.
  • Disable or block access to internal-only API paths at the perimeter until the vendor patch is applied.

Key dates

Published (NVD)
July 27, 2026
Added to CISA KEV
July 27, 2026
Remediation deadline
July 30, 2026
Last updated
July 28, 2026

References

Frequently asked questions

Does CVE-2026-16812 affect my FedRAMP authorization?

If Arista VeloCloud Orchestrator runs inside your authorization boundary, CVE-2026-16812 is your problem to resolve. CISA has listed this vulnerability in the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of July 30, 2026. An unpatched KEV inside your boundary is an assessor finding: you either remediate it or formally document a mitigation before your assessor or sponsoring agency raises it as a deficiency.

How does Knox help me handle CVE-2026-16812?

Remediating Arista VeloCloud Orchestrator is your responsibility under the FedRAMP shared-responsibility model; Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage that document your fix for the next assessment cycle. The work is yours to execute; maintaining a compliant posture while you execute it is not something you carry alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-16812, on an ongoing basis. Exposure surfaces during continuous monitoring rather than waiting to be flagged at an assessor review, giving your team time to act before a finding becomes a formal deficiency.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60–80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-16812 isn't remediated by July 30, 2026?

If you miss the July 30, 2026 deadline, CVE-2026-16812 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list turns a routine continuous-monitoring review into a hard agency conversation. If you meet the deadline, you'll keep your authorization clean and your sponsoring agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting