Wire Observer.
Technology

Arista Issues Emergency Patches for Actively Exploited VeloCloud Orchestrator Zero‑Day

Arista Networks announced the release of emergency security updates to address a zero‑day vulnerability in its VeloCloud Orchestrator (VCO) on‑premises software that is currently being weaponised by threat actors.

VCO is the central management component of Arista's SD‑WAN solution, coordinating traffic routing, policy enforcement and performance monitoring across distributed branch sites. Many enterprises run VCO in a private data centre rather than in the cloud to retain tighter control over their network fabric, making the on‑premises deployment a critical target for attackers seeking to disrupt corporate connectivity.

While the technical details of the flaw have not been fully disclosed, security analysts have confirmed that it can be triggered remotely without authentication, potentially allowing malicious code execution or unauthorized configuration changes. The fact that the vulnerability is already being exploited in the wild raises the urgency for organisations that rely on VCO to remediate the issue immediately.

In response, Arista issued a security advisory alongside patches that close the identified attack vector. The company urged all customers with on‑prem VCO installations to download and apply the updates without delay. Arista also provided guidance on verifying patch installation and recommended that administrators review system logs for any signs of suspicious activity that may have occurred before the fix was applied.

Security best practices suggest that organisations should complement the patch with additional safeguards such as restricting access to the VCO management interface, enabling multi‑factor authentication where possible, and isolating the orchestrator from untrusted networks. For environments where immediate patching is not feasible, temporary network segmentation or firewall rules that block unknown inbound traffic to the VCO host can help mitigate exposure.

The incident underscores a broader trend of attackers targeting networking infrastructure, a sector traditionally perceived as less vulnerable than end‑user devices. As enterprises adopt increasingly software‑defined networking solutions, the attack surface expands, prompting vendors like Arista to accelerate vulnerability disclosure and remediation cycles.

Arista has indicated that it will continue monitoring the situation and stands ready to release further updates if additional weaknesses are uncovered. Customers are advised to stay informed through the company's security portal and to engage with their security teams to ensure that any lingering threats are fully eradicated.

Aarav Mehta — Technology desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related