Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
This functionality was intended to be for internal use only and is not intended to be remotely accessible.
Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out.
This issue was discovered externally and is known to be actively exploited.
VeloCloud Orchestrator (VCO) On-Prem exposes an internal privileged functionality endpoint to the network that was designed for internal use only. Because the endpoint fails to sanitize attacker-supplied input before passing it to OS-level command execution (CWE-78), shell metacharacters or injected command strings in the request are interpreted and executed by the host operating system. No authentication is required to reach the endpoint, and the flaw is confirmed as actively exploited in the wild.
An attacker with network access to the VCO management interface sends crafted requests containing OS command injection payloads to the exposed internal endpoint. No credentials or user interaction are needed. Successful exploitation yields arbitrary OS command execution on the VCO host, resulting in full compromise of confidentiality, integrity, and availability of the orchestrator and all SD-WAN configuration and policy data it manages. Only on-prem deployments running affected versions are exposed; hosted and dedicated VCO instances were patched before public disclosure.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Arista VeloCloud Orchestrator runs inside your authorization boundary, CVE-2026-16812 is your problem to resolve. CISA has listed this vulnerability in the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of July 30, 2026. An unpatched KEV inside your boundary is an assessor finding: you either remediate it or formally document a mitigation before your assessor or sponsoring agency raises it as a deficiency.
Remediating Arista VeloCloud Orchestrator is your responsibility under the FedRAMP shared-responsibility model; Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage that document your fix for the next assessment cycle. The work is yours to execute; maintaining a compliant posture while you execute it is not something you carry alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-16812, on an ongoing basis. Exposure surfaces during continuous monitoring rather than waiting to be flagged at an assessor review, giving your team time to act before a finding becomes a formal deficiency.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60–80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
If you miss the July 30, 2026 deadline, CVE-2026-16812 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list turns a routine continuous-monitoring review into a hard agency conversation. If you meet the deadline, you'll keep your authorization clean and your sponsoring agency relationship intact.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









