Knox CVE Database
/
CVE-2026-16812
Critical
10.0

CVE-2026-16812: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Added to the CISA KEV catalog:
July 27, 2026

Overview

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

This functionality was intended to be for internal use only and is not intended to be remotely accessible.

Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out.

This issue was discovered externally and is known to be actively exploited.

Vulnerability details

Affected vendor
Arista
Affected product
VeloCloud Orchestrator
Weakness type (CWE)
CWE-78

VeloCloud Orchestrator (VCO) on-premises deployments contain an OS command injection flaw (CWE-78) in an internal privileged endpoint that was not designed to be network-accessible. The application passes attacker-supplied input to an OS command interpreter without sanitizing shell metacharacters or injected command strings, allowing the injected commands to execute in the context of the orchestrator process. Because no authentication is required and the endpoint is reachable over the network, the attack surface is the full network perimeter of any exposed VCO instance.

An attacker sends a crafted network request containing OS command injection payloads to the exposed internal endpoint. No credentials, user interaction, or prior access are required. Successful exploitation yields arbitrary OS command execution on the VCO host, giving the attacker full control over the orchestrator and all SD-WAN configuration, policy, and credential data it manages. This vulnerability affects only on-premises deployments; hosted and dedicated instances were patched before public disclosure. Active exploitation has been confirmed externally.

Severity and impact

10.0
Critical
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review VCO host OS-level process logs for unexpected child processes spawned by the orchestrator service, particularly shells (bash, sh, cmd) or network utilities with no corresponding administrative session in the VCO audit log.
  • Audit network flow logs for inbound connections to VCO management ports originating from sources outside the defined administrative IP ranges, especially where no corresponding authenticated management session exists in application logs.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 30, 2026

Additional hardening

  • Restrict network access to VCO management interfaces using firewall rules or ACLs, permitting only explicitly authorized administrative source addresses.
  • Place on-premises VCO instances behind a network perimeter that blocks direct internet access to management ports until the vendor patch is applied.
  • Conduct forensic triage per CISA guidance to determine whether the host was accessed prior to patching, given confirmed active exploitation.
  • Disable or isolate the VCO host from managed edge devices if patching cannot be applied immediately, to limit lateral impact across the SD-WAN fabric.

Key dates

Published (NVD)
July 27, 2026
Added to CISA KEV
July 27, 2026
Remediation deadline
July 30, 2026
Last updated
July 28, 2026

References

Frequently asked questions

Does CVE-2026-16812 affect my FedRAMP authorization?

If Arista VeloCloud Orchestrator runs inside your authorization boundary, yes. CVE-2026-16812 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, which carries a remediation deadline of July 30, 2026. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding — one you either remediate or formally document a mitigation for before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2026-16812?

Knox doesn't patch your software for you — remediating Arista VeloCloud Orchestrator is your responsibility under the FedRAMP shared responsibility model. What Knox gives you is the pre-authorized, single-tenant boundary to remediate in, plus continuous compliance monitoring and audit-artifact coverage that help you document the fix for your next assessment. The fix is yours to apply; staying compliant while you apply it isn't something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's continuous monitoring, powered by KnoxAI, watches your environment in real time for newly disclosed vulnerabilities and compliance issues. Exposure surfaces as part of ongoing monitoring — not only when an assessor flags it at review time.

How do I get FedRAMP authorized with Knox?

Book a meeting and Knox maps your path — FedRAMP in 90 days for 90% less, without dependency or delay.

What happens if CVE-2026-16812 isn't remediated by July 30, 2026?

It becomes a POA&M item, and a growing POA&M list is what turns a routine continuous-monitoring review into a real conversation with your agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.

What this vulnerability means for your FedRAMP compliance

Because this flaw is in CISA's Known Exploited Vulnerabilities catalog, FedRAMP continuous monitoring puts a hard remediation clock on it. The clock starts on awareness — and missing the deadline can put an Authority to Operate at risk.

FedRAMP remediation deadlines for actively exploited vulnerabilities

FedRAMP ConMon SLAs give cloud providers 30, 90, or 180 days by severity — but KEV-listed flaws carry the tighter CISA deadline shown above. For authorized services, that date is the compliance line that assessors and agency sponsors will check.

How Knox reduces the burden of CVE vulnerabilities

Remediating the flaw is your responsibility under the FedRAMP shared responsibility model — but staying compliant while you fix it isn't something you manage alone. KnoxAI's continuous monitoring surfaces exposure in real time, and Knox keeps your continuous-monitoring evidence and audit artifacts current while you apply the fix. Learn more about the Knox platform.

How to limit your exposure through inherited controls and isolation

Knox's single-tenant architecture gives every customer a dedicated boundary, and 60–80% of FedRAMP controls are inherited from the platform — shrinking the surface you have to patch and prove. See why teams choose Knox.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting