CISA KEV: Patch Arista VeloCloud Orchestrator CVE-2026-16812 Now
July 28, 2026
Arista VeloCloud Orchestrator On-Prem has a critical, actively exploited security issue tracked as CVE-2026-16812. CISA added it to the Known Exploited Vulnerabilities catalog on July 27, 2026. If your organization operates VeloCloud Orchestrator on-premises, treat this as an urgent security and recovery task.
Arista says the issue can let a remote attacker reach privileged internal functionality and affect the orchestrator host. A successful compromise can affect the orchestrator and the network data it manages. This guide keeps the response focused on vendor-supported remediation, access reduction, and recovery checks. It does not describe how to test or trigger the issue.
First confirm whether your deployment is in scope
- Prioritize VeloCloud Orchestrator On-Prem. Arista lists 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1 as affected.
- Arista states that its Hosted and Dedicated VCO services were patched before the public advisory. VeloCloud Gateway and VeloCloud Edge are not affected by this specific issue.
- Do not assume an end-of-support release is safe because it is absent from an inventory report. Arista says unsupported trains were not assessed; contact Arista TAC for the supported upgrade path.
Contain exposure while the update is scheduled
- Restrict VCO web administration to the approved administrative networks and access paths for your organization. Keep the change narrow and record the owner who validates emergency access.
- Check that public exposure is intentional. Arista notes that VCO is exposed by default and that credentials are not required for the reported exposure.
- Preserve normal logging and monitoring. Review unexpected VCO administration, unusual outbound activity from the host, and configuration changes that do not match an approved change record.
- Tell network, incident-response, and service-desk owners about the maintenance window before changing access controls or upgrading the orchestrator.
Upgrade to Arista’s remediated release
Use Arista’s supported software process and maintenance guidance for the VCO release train you run. Arista lists remediated 5.2.3.14, 6.1.3.4, and 6.4.2.4 releases and later within those trains. For 7.0 deployments, move to 7.0.0.1 or later as indicated by the affected-version boundary, and confirm the final target with Arista before beginning a production change.
Before the change, identify the VCO version, cluster or appliance role, approved maintenance window, configuration owners, current recovery plan, and dependent SD-WAN services. Use the vendor’s release notes for prerequisites and rollback limits. Do not combine this security update with an unrelated policy redesign, identity migration, or WAN modernization project.
Post-update and compromise review
- Confirm the installed VCO release and normal administrative access through the approved route.
- Validate a representative managed-device workflow, expected policy state, monitoring, and alert delivery.
- Review recent administrator activity, sensitive configuration changes, and host or application logs around the exposure period.
- If suspicious activity is found, follow your incident-response process. Arista recommends considering credential rotation, validation of managed-device state, and restoration or replacement from trusted sources where appropriate.
Keep the hosting and application estate coordinated
Network-control-plane maintenance can affect public applications even when the application itself is unchanged. After the VCO work, validate representative external services and use the Fix I.T. Phill WordPress Support hub for the separate site, cache, and business-workflow checks that may be needed. For a broader patch-planning pattern, see our Proxmox VE security patch checklist.

