Arista Rolls Out Critical Patches for Actively Exploited VeloCloud Orchestrator Zero‑Day
Arista Networks has issued emergency security updates to fix a zero‑day flaw in its on‑premises VeloCloud Orchestrator (VCO) software that threat actors are already exploiting.
VCO serves as the core management element of Arista's SD‑WAN offering, handling traffic routing, policy enforcement and performance monitoring across dispersed branch locations. Because many organizations prefer to host VCO in a private data centre rather than in the cloud to maintain tighter control over their network fabric, the on‑premises version has become a prime target for attackers aiming to disrupt corporate connectivity.
Although the full technical specifics of the vulnerability have not been released, security researchers have verified that it can be triggered remotely without authentication, potentially enabling execution of malicious code or unauthorized configuration changes. The fact that the flaw is already being leveraged in the wild makes rapid remediation essential for any organization relying on VCO.
In reaction, Arista published a security advisory together with patches that seal the identified attack vector. The firm urged every customer running on‑prem VCO to download and install the fixes immediately. It also supplied instructions for confirming patch deployment and advised administrators to examine system logs for any suspicious activity that might have occurred before the update.
Best‑practice guidance recommends pairing the patch with further defenses such as limiting access to the VCO management interface, enabling multi‑factor authentication where feasible, and isolating the orchestrator from untrusted networks. For sites unable to apply the patch right away, temporary network segmentation or firewall rules that block unknown inbound traffic to the VCO host can reduce exposure.
The episode highlights a growing pattern of threat actors focusing on networking infrastructure, a layer traditionally seen as less vulnerable than end‑user devices. As more enterprises adopt software‑defined networking solutions, the attack surface widens, prompting vendors like Arista to speed up vulnerability disclosure and remediation timelines.
Arista says it will keep monitoring the situation and stands ready to issue additional updates should further weaknesses emerge. Customers should stay tuned to the company's security portal and coordinate with their security teams to ensure any remaining threats are fully eliminated.
Comments (0)
Be the first to comment.
Join the discussion