CVE-2026-16812 is a critical, exploited vulnerability affecting on-premises VeloCloud Orchestrator. Arista states that hosted and dedicated orchestrator services were patched by the provider; customer-managed on-premises instances require owner action.
Current as of 2026-08-15
Arista security advisory 0144 lists fixed releases 5.2.3.14, 6.1.3.4, 6.4.2.4, 7.0.0.1, and later applicable builds. CISA’s KEV catalog added CVE-2026-16812 on July 27.
Decision summary
- Determine whether the orchestrator is provider-hosted, dedicated, or customer-managed on premises.
- Do not assume a hosted-service patch remediated an on-premises deployment.
- Upgrade every affected instance to an applicable fixed release.
- Investigate exposed management interfaces and preserve evidence before destructive recovery.
Resolve ownership and exposure
- Orchestrator deployment model and accountable owner.
- Exact software version and build.
- Internet-facing management interfaces and access controls.
- Administrative identities, SSO, API tokens, and automation.
- Logs available for the exposure window.
- Standby, disaster-recovery, and lab instances.
Patch in a controlled sequence
Back up configuration and platform data, confirm the supported upgrade path, apply the fixed release, and verify the running version. Test administrator authentication, edge management, configuration delivery, telemetry, alarms, API integrations, and HA.
Reduce management exposure
- Restrict access to trusted management networks or approved paths.
- Require strong administrator authentication and least privilege.
- Remove stale accounts and tokens.
- Centralize audit logs and alert on high-risk changes.
- Separate orchestrator administration from routine user networks.
Investigate when warranted
Known exploitation establishes urgency, not proof that a particular instance was compromised. Correlate unexpected logins, configuration changes, new accounts, API use, processes, files, and network activity. Escalate to incident response when integrity cannot be established.
For related guidance from ITECS, see ITECS managed network services.
Sources and update trigger
Review trigger: Recheck the vendor advisory and KEV entry immediately before remediation and when fixed releases or indicators change.
