Critical Unauthenticated Remote Code Execution in VeloCloud Orchestrator Exposes SD-WAN Infrastructure
Overview
CVE-2026-16812 represents a CVSS 10.0 vulnerability in VeloCloud Orchestrator (VCO) on-prem installations, enabling unauthenticated remote attackers to access privileged internal APIs and fully compromise orchestrator hosts and managed SD-WAN networks. Exploitation is currently active in the wild.
Technical Analysis
The vulnerability stems from improperly restricted internal management APIs exposed on ports 443/8443 without authentication requirements. Attackers can execute arbitrary commands on the VCO host by crafting HTTP requests targeting internal-only endpoints, achieving remote code execution and lateral movement to SD-WAN edge devices. Exploitation does not require credentials, credentials reuse, or user interaction, enabling trivial remote compromise.
Enterprise & DIB Impact
Defense Industrial Base (DIB) entities and enterprises relying on VMware SD-WAN infrastructure face imminent risk of total network control-plane compromise. Attackers could manipulate traffic routing, decrypt sensitive telemetry data, or disrupt mission-critical connectivity in environments using unpatched on-prem VCO deployments.
Recommended Actions
- Immediately apply the hosted/dedicated VCO patches provided by VMware
- block inbound traffic to VCO management ports from untrusted networks
- enable API logging and monitor for anomalous authentication-less API requests
- disable unused internal endpoints via configuration hardening
- and review third-party access permissions to SD-WAN infrastructure.
Need Help Assessing Your Exposure?
Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.
Schedule a ConsultationFull security advisory on 247alerts.net →