Arista's SD-WAN box has a bug so bad hackers don't even need a password

CVE-2026-16812 scores a perfect 10, needs zero credentials, and CISA is already watching it get used against real networks.

Aliteq
Ravi Malhotra · Hardware Editor

What you need to know

CVE-2026-16812 is an unauthenticated OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), scoring a perfect 10.0 on both CVSSv3.1 and CVSSv4.0.

What you need to know

No VCO tenant or operator credentials are required — only network reachability to the web interface — and Arista's own advisory confirms it is being actively exploited.

What you need to know

Fixed versions: 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. Only on-premises VCO is affected; Arista's hosted and dedicated VCO instances were already patched before disclosure.

What you need to know

CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog, giving federal agencies a 3-day patch deadline under Binding Operational Directive 26-04.

My take

A perfect 10.0 with confirmed active exploitation and zero authentication required is about as close to 'drop everything' as CVE scoring gets. If your team is still routing this through a normal…

Aliteq

Read the full story

Arista's SD-WAN box has a bug so bad hackers don't even need a password

Read the full story on Aliteq