The bug, tracked as CVE-2026-16812, lives in VeloCloud Orchestrator On-Prem, the self-hosted version of software that companies use to centrally manage their SD-WAN networks connecting branch offices, data centers, and cloud environments. Here’s the uncomfortable part for anyone running this in-house: Arista says the on-premises orchestrator ships with that exposure baked in by default, and there’s no setting that fully closes it off. Arista released three IP addresses linked to active attacks but stopped short of naming who sits behind them, when the exploitation started, or how many customers took a hit. Arista says it already patched the hosted and dedicated versions of the orchestrator before publishing the advisory, so customers running those services don’t need to take action. Everyone else running the on-premises version needs to upgrade to 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1 immediately.