HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Remote Code Execution Vulnerability (CVE‑2026‑16812) in VeloCloud Orchestrator On‑Prem Exposes Enterprise SD‑WAN Management

A CVE‑2026‑16812 flaw in VeloCloud Orchestrator on‑prem versions enables unauthenticated remote code execution and is being actively exploited. Enterprises must map remediation to SOC 2 controls to maintain audit readiness.

LiveThreat™ Intelligence · 📅 July 28, 2026· 📰 cisecurity.org
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
cisecurity.org

Remote Code Execution Vulnerability (CVE‑2026‑16812) in VeloCloud Orchestrator On‑Prem Exposes Enterprise SD‑WAN Management

What Happened — A newly disclosed vulnerability (CVE‑2026‑16812) in VeloCloud Orchestrator (VCO) on‑prem versions prior to 5.2.3.14, 6.1.3.4, 6.4.2.4 and 7.0.0.1 allows an unauthenticated remote attacker to execute code on the VCO host. The vendor confirms the flaw is being actively exploited from several public IPs.

Why It Matters for Compliance & Audit Readiness

  • The flaw bypasses authentication and can be used to alter configuration, install software, or create privileged accounts – a classic violation of SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations).
  • Continuous‑compliance programs must map such vulnerabilities to control evidence, demonstrate timely patching, and retain logs that prove remediation actions were taken.
  • Verisq’s Control Mapping capability automates the linkage between CVE remediation tickets and SOC 2 control evidence, creating a defensible audit trail.

Who Is Affected — Enterprises that deploy VeloCloud SD‑WAN/SASE on‑prem, spanning government agencies, large‑ and medium‑size businesses, and service providers.

Recommended Actions

  • Immediately apply the vendor‑provided patches (VCO 5.2.3.14, 6.1.3.4, 6.4.2.4, 7.0.0.1 or later).
  • Map the CVE to SOC 2 CC6.1 and CC7.1 controls, capture patch‑installation logs, and store them in a tamper‑evident repository.
  • Enable network segmentation and restrict access to the VCO web interface to trusted management subnets only.
  • Integrate vulnerability‑remediation tickets with your continuous‑compliance dashboard to maintain real‑time audit evidence.

Source: CIS Advisory 2026‑072

Technical Notes

  • Attack Vector: Exploit Public‑Facing Application (T1190). No credentials required; attacker needs network reach to the VCO web UI.
  • CVSS (reported): Not disclosed, but the remote code execution potential and active exploitation place it in the High severity band.
  • Affected Versions: VCO 5.2.x < 5.2.3.14, 6.1.x < 6.1.3.4, 6.4.x < 6.4.2.4, 7.0.x < 7.0.0.1.
📰 Original Source
https://www.cisecurity.org/advisory/a-vulnerability-in-velocloud-orchestrator-vco-on-prem-could-allow-for-remote-code-execution_2026-072

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →