A critical security vulnerability (CVE-2026-16812) has been identified in VeloCloud Orchestrator (VCO) on-premises deployments. The flaw stems from an improperly restricted internal API endpoint that could be accessed remotely, enabling attackers to execute privileged operations. Successful exploitation may lead to full compromise of the orchestrator host and associated data, impacting confidentiality, integrity, and availability. Hosted and dedicated VCO versions have already been patched by vendors. On-premises users must apply updates immediately to mitigate risk. The vulnerability was discovered externally and is confirmed to be actively exploited in the wild. Organizations running affected versions should prioritize remediation, disable unnecessary network exposure to VCO systems, and monitor for anomalous API activity. This issue underscores the importance of strict access controls for internal-facing components. No workarounds are available for unpatched systems. Affected products include VeloCloud Orchestrator Platform and VeloCloud Appliance.
CRITICAL
CVSS 10.0
CVE-2026-16812
2026-08-14
Critical Remote Code Execution Vulnerability in VeloCloud Orchestrator (CVE-2026-16812)
A critical vulnerability in VeloCloud Orchestrator allows remote attackers to access privileged internal functionality, risking data confidentiality, integrity, and availability. Immediate patching is required for on-premises deployments.