Security researchers have issued a warning about a critical command injection vulnerability being actively exploited in on-premises VeloCloud Orchestrator (VCO) deployments This article explores velocloud orchestrator vco. . This vulnerability, tracked as CVE-2026-16812, allows remote attackers to access privileged internal functions and potentially gain control of the VeloCloud Orchestrator host.
The flaw has received the highest severity score of 10.0 in both CVSS v3.1 and CVSS v4.0. VeloCloud Orchestrator is utilized to manage SD-WAN environments, encompassing connected VeloCloud Edge devices, network configurations, certificates, and other sensitive operational data. Exploit VCO Command Injection Vulnerability Based on the security advisory, the vulnerable functionality was intended for internal use only; however, it is accessible remotely in affected on-premises VCO installations.
Affected versions include VCO 5.2.x releases prior to 5.2.3.14, VCO 6.1.x releases prior to 6.1.3.4, VCO 6.4.x releases prior to 6.4.2.4, and VCO 7.0.x releases prior to 7.0.0.1. They should also monitor the VCO host for suspicious inbound requests, unexpected outbound HTTP or HTTPS traffic, unexplained configuration changes, and unusual maintenance operations. There is no definitive sign of compromise, but administrators must scrutinize web requests containing unusual URL path segments, encoded characters, references to local services, or high volumes of requests.
Since an exploited orchestrator could expose managed VeloCloud Edge devices, organizations should rotate credentials, validate device states, review administrator actions, and restore affected systems only from trusted sources to strengthen their SOC.












