CVE-2026-16812: Arista VeloCloud Orchestrator's Actively Exploited Command Injection Zero-Day
Technical breakdown of the actively exploited pre-auth command injection zero-day in Arista VeloCloud SD-WAN Orchestrator.
Threat actors actively exploited a pre-authentication command injection zero-day in Arista VeloCloud SD-WAN Orchestrator, enabling remote attackers to hijack software-defined enterprise WAN deployments.
CVE-2026-16812 (CWE-78: OS Command Injection)
Severity: Critical 9.8 (Zero-Day In-The-Wild)
Target: Arista / VMware VeloCloud SD-WAN Orchestrator portal
What's Affected
Arista VeloCloud Orchestrator portals exposed to the public internet without IP allowlisting.