In gymnastics, a perfect 10 gets you a gold medal. In vulnerability scoring, a perfect 10 gets you a very bad week, a call from CISA, and a deadline scrawled on every network admin's calendar in red ink.
Command Injection, Zero Auth Required
Arista has patched a maximum-severity flaw in on-premises deployments of VeloCloud Orchestrator (VCO), the centralized platform that manages VeloCloud SD-WAN edge devices. Tracked as CVE-2026-16812 and scoring a flawless 10.0 on the CVSS scale, the bug is an unauthenticated OS command injection — meaning an attacker doesn't need a password, a phished credential, or a foothold. They just need the orchestrator's web interface exposed to the internet, which, inconveniently, it is by default with no option to fully lock it down.
Arista confirmed the flaw is already being actively exploited in the wild, though it hasn't disclosed when the attacks started or who's behind them. Three attacker IP addresses have been publicly identified. Fixes landed in versions 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1 — hosted and dedicated VCO deployments were already patched before the advisory even went public.
Why Your SD-WAN Just Became Everyone's Problem
Compromising the orchestrator doesn't just hand attackers the keys to a management console — Arista warns it can cascade into access on the VeloCloud Edge devices themselves, the boxes actually routing traffic for the network. That's the difference between someone peeking at your dashboard and someone rerouting your entire branch office's internet.
CISA wasted no time adding CVE-2026-16812 to its Known Exploited Vulnerabilities catalog, giving federal agencies until July 30, 2026 — basically no runway at all — to patch. If you're running VCO on-prem and haven't updated yet, restricting web interface access to trusted management networks is your stopgap, but "stopgap" is doing a lot of heavy lifting when the alternative is arbitrary code execution.
A perfect score is great in the Olympics and nowhere else — patch now, ask questions later.
Want a second set of eyes on your own setup? We'd be happy to look.
Source: The Register