Remote Code Execution Vulnerability (CVE‑2026‑16812) in VeloCloud Orchestrator On‑Prem Exposes Enterprise SD‑WAN Management
What Happened — A newly disclosed vulnerability (CVE‑2026‑16812) in VeloCloud Orchestrator (VCO) on‑prem versions prior to 5.2.3.14, 6.1.3.4, 6.4.2.4 and 7.0.0.1 allows an unauthenticated remote attacker to execute code on the VCO host. The vendor confirms the flaw is being actively exploited from several public IPs.
Why It Matters for Compliance & Audit Readiness
- The flaw bypasses authentication and can be used to alter configuration, install software, or create privileged accounts – a classic violation of SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations).
- Continuous‑compliance programs must map such vulnerabilities to control evidence, demonstrate timely patching, and retain logs that prove remediation actions were taken.
- Verisq’s Control Mapping capability automates the linkage between CVE remediation tickets and SOC 2 control evidence, creating a defensible audit trail.
Who Is Affected — Enterprises that deploy VeloCloud SD‑WAN/SASE on‑prem, spanning government agencies, large‑ and medium‑size businesses, and service providers.
Recommended Actions
- Immediately apply the vendor‑provided patches (VCO 5.2.3.14, 6.1.3.4, 6.4.2.4, 7.0.0.1 or later).
- Map the CVE to SOC 2 CC6.1 and CC7.1 controls, capture patch‑installation logs, and store them in a tamper‑evident repository.
- Enable network segmentation and restrict access to the VCO web interface to trusted management subnets only.
- Integrate vulnerability‑remediation tickets with your continuous‑compliance dashboard to maintain real‑time audit evidence.
Source: CIS Advisory 2026‑072
Technical Notes —
- Attack Vector: Exploit Public‑Facing Application (T1190). No credentials required; attacker needs network reach to the VCO web UI.
- CVSS (reported): Not disclosed, but the remote code execution potential and active exploitation place it in the High severity band.
- Affected Versions: VCO 5.2.x < 5.2.3.14, 6.1.x < 6.1.3.4, 6.4.x < 6.4.2.4, 7.0.x < 7.0.0.1.