CVE-2026-16812
VeloCloud Orchestrator (VCO) on-prem contains a critical vulnerability (CVSS 10) that lets a remote attacker reach privileged internal functions, potentially compromising the orchestrator's confidentiality, integrity, and availability. The issue is actively exploited in the wild. Hosted and Dedicated VCO versions have already been patched, but the advisory does not confirm a patch for the on‑prem product.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
VeloCloud Orchestrator (VCO) on-prem
Real-world impact
Attackers can access internal functionality and affect confidentiality, integrity, and availability of the orchestrator and its data.
Why this severity
CVSS base score 10 (Critical) with network‑adjacent attack vector, low complexity, no privileges or user interaction required, and high impact across all security properties.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 27, 2026 · 5d agoConfirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jul 27, 2026 · 5d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 2d agoCISA remediation deadlineFederal agencies are required to remediate by this date.
How it’s attacked
References & advisories
- arista.com/en/support/advisories-notic…mitigationvendor advisory
- cisa.gov/known-exploited-vulnerabili…us government resource