A critical security vulnerability (CVE-2026-16812) has been identified in VeloCloud Orchestrator (VCO) on-premises deployments. The flaw stems from an improperly restricted internal API endpoint that could be accessed remotely, enabling attackers to execute privileged operations. Successful exploitation may lead to full compromise of the orchestrator host and associated data, impacting confidentiality, integrity, and availability. Hosted and dedicated VCO versions have already been patched by vendors. On-premises users must apply updates immediately to mitigate risk. The vulnerability was discovered externally and is confirmed to be actively exploited in the wild. Organizations running affected versions should prioritize remediation, disable unnecessary network exposure to VCO systems, and monitor for anomalous API activity. This issue underscores the importance of strict access controls for internal-facing components. No workarounds are available for unpatched systems. Affected products include VeloCloud Orchestrator Platform and VeloCloud Appliance.