← Back to Research Blog
CRITICAL CVE-2026-16812

Critical Unauthenticated Remote Code Execution in VeloCloud Orchestrator Exposes SD-WAN Infrastructure

10.0
CRITICAL
velocloud orchestrator, vmware velocloud
2026-08-14

Overview

CVE-2026-16812 represents a CVSS 10.0 vulnerability in VeloCloud Orchestrator (VCO) on-prem installations, enabling unauthenticated remote attackers to access privileged internal APIs and fully compromise orchestrator hosts and managed SD-WAN networks. Exploitation is currently active in the wild.


Technical Analysis

The vulnerability stems from improperly restricted internal management APIs exposed on ports 443/8443 without authentication requirements. Attackers can execute arbitrary commands on the VCO host by crafting HTTP requests targeting internal-only endpoints, achieving remote code execution and lateral movement to SD-WAN edge devices. Exploitation does not require credentials, credentials reuse, or user interaction, enabling trivial remote compromise.

Enterprise & DIB Impact

Defense Industrial Base (DIB) entities and enterprises relying on VMware SD-WAN infrastructure face imminent risk of total network control-plane compromise. Attackers could manipulate traffic routing, decrypt sensitive telemetry data, or disrupt mission-critical connectivity in environments using unpatched on-prem VCO deployments.

Recommended Actions

Need Help Assessing Your Exposure?

Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.

Schedule a Consultation
Full security advisory on 247alerts.net →
Axiom Cyber Research
Axiom Cyber Research, LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing elite cybersecurity consulting to the Defense Industrial Base and regulated sectors. Founded by a 20+ year veteran with deep offensive and defensive cyber expertise. Our CVE intelligence program actively tracks emerging vulnerabilities to help organizations prioritize remediation and reduce exposure windows.
Baltimore, MD  ·  axiomcyber.io  ·  247alerts.net  ·  SDVOSB  ·  NAICS 541512