Full Report
Arista Networks security advisory (AV26-751)
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in Arista VeloCloud Orchestrator (including CVE-2026-16812)
## CVE Details
- **CVE ID:** CVE-2026-16812 (Note: Advisory covers multiple flaws; this is the primary critical identifier mentioned).
- **CVSS Score:** Not explicitly listed in the bulletin, but classified as high-priority by CISA.
- **CWE:** Not specified in the source.
## Affected Systems
- **Products:** VeloCloud Orchestrator On-Prem
- **Versions:**
- 5.2.0 to versions prior to 5.2.3.14
- 6.1.0 to versions prior to 6.1.3.4
- 6.4.0 to versions prior to 6.4.2.4
- 7.0.0 to versions prior to 7.0.0.1
- **Configurations:** Systems running On-Prem installations of the VeloCloud Orchestrator software.
## Vulnerability Description
While the provided bulletin does not detail the exact technical mechanism (e.g., Buffer Overflow, SQLi, etc.), the inclusion of CVE-2026-16812 in the CISA KEV (Known Exploited Vulnerabilities) catalog indicates a critical flaw that allows for significant unauthorized action or system compromise. Based on the "Orchestrator" product type, such flaws typically involve remote code execution (RCE) or authentication bypass within the management plane.
## Exploitation
- **Status:** **Exploited in the wild.** (Added to CISA KEV on July 27, 2026).
- **Complexity:** Not specified; however, KEV status implies reliable exploitation is possible.
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High
- **Integrity:** High
- **Availability:** High
*(Impact assessed based on KEV status and Orchestrator role in SD-WAN architecture)*
## Remediation
### Patches
Arista Networks has released the following fixed versions:
- Upgrade to version **5.2.3.14** or higher
- Upgrade to version **6.1.3.4** or higher
- Upgrade to version **6.4.2.4** or higher
- Upgrade to version **7.0.0.1** or higher
### Workarounds
- No specific software workarounds were provided in the summary. Organizations should prioritize patching.
- General mitigation involves restricting access to the Orchestrator management interface to trusted IP addresses only.
## Detection
- **Indicators of Compromise:** Users should monitor for unauthorized administrative logins or unexpected configuration changes within VeloCloud Orchestrator.
- **Detection methods and tools:** Consult the CISA KEV catalog and Arista Security Advisories 0144/0145 for specific log signatures or forensic artifacts associated with the exploitation of CVE-2026-16812.
## References
- Arista Security Advisory 0144: hxxps[://]www[.]arista[.]com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
- Arista Security Advisory 0145: hxxps[://]www[.]arista[.]com/en/support/advisories-notices/security-advisory/24365-security-advisory-0145
- CISA KEV Catalog: hxxps[://]www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16812
- Government of Canada Bulletin: hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/arista-networks-security-advisory-av26-751