Arista
– Getty Images

Arista Networks patched a critical security flaw in its Broadcom-inherited management platform.

The flaw in question concerns VeloCloud Orchestrator (VCO) On-Prem, Arista’s centralized management suite for configuring, monitoring, and managing SD-WAN deployments. Marked as CVE-2026-16812, it gives way for a remote attacker to access privileged internal functionality and compromise the host system.

Arista admitted VCO is “exposed by default,” meaning there is no configuration that can avert the exposure. A successful attack only requires network access to the VCO web interface, with VCO tenant or operator credentials not required for this exposure.

The networking firm added the issue is being actively exploited. It did not share further details on these exploits nor who they have affected.

Arista made patches available for VCO versions 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. It also recommended operators thoroughly review VCO web access, backend application, and system logs for suspicious activity, and block certain IPs: 8.19.75.217, 206.72.242.124, and 206.72.242.162, from which it recorded malignant activity.

Should a compromise be suspected, Arista advised all log data and file-system timestamps must be preserved before remediation. Until patches are deployed, users should restrict web interface access to trusted administrative networks and closely monitor for the aforementioned IPs, unauthorized changes, and any unexpected network connections.

According to Arista, the flaw was discovered externally, meaning it was not picked up following its acquisition of VeloCloud from Broadcom last summer. That deal placed Arista closer to making its name in secure access service edge (SASE), something developed with last week's release of an edge threat solution to its VeloCloud SD-WAN suite. Analysts suggested at the time of the acquisition that Arista would be poised to snap up a cybersecurity or security service edge (SSE) player next in its security ambitions.

It's worth noting that the default nature of the VCO flaw suggests Broadcom missed it too when acquiring VeloCloud from VMware almost a decade ago, marking out the vulnerability as the long-dormant sort that AI-driven bug hunters from Anthropic and OpenAI claim to be specialized in finding.