🔐
Security 📅 2026-07-28 · 09:47 AM IST ⏱ 2 min read

Arista's Cloud Management Tool Under Active Attack Through Previously Unknown Security Flaw

Attackers exploit unpatched Arista VeloCloud Orchestrator software to gain unauthorized system access on company networks.

A Major Network Management Tool Gets Compromised

Arista Networks, a company that makes software for managing cloud and network connections, has discovered that hackers are actively exploiting a serious security weakness in its VeloCloud Orchestrator product. The flaw allows attackers to run commands on computers running this software without proper permission or authentication—essentially giving them a master key to sensitive systems.

This vulnerability is particularly dangerous because it has been weaponized in real attacks before a fix was publicly released. Security researchers call this a "zero-day" issue, meaning attackers discovered and began exploiting the weakness before the company even knew it existed.

How The Attack Works

Think of VeloCloud Orchestrator as a control center for a company's branch office connections and cloud services. It's the nerve center that manages how traffic flows through a network. The vulnerability discovered allows someone to inject malicious instructions directly into this system—similar to sneaking commands into a cashier's computer at a bank to make it perform unauthorized transactions.

The flaw specifically affects organizations running this software on their own servers (called "on-premises" deployments), rather than renting it from Arista's cloud service. Attackers can exploit this to gain administrative-level access, giving them deep control over the network infrastructure that many businesses depend on daily.

What This Means

This discovery affects companies across various industries that use Arista's tools to manage their network operations. If your organization relies on VeloCloud Orchestrator to connect branch offices or manage traffic to cloud services, your infrastructure could be at risk.

The fact that attacks are already happening makes this urgent. This isn't a theoretical problem researchers found in a lab—real attackers are actively trying to break into systems using this weakness right now.

Why You Should Care

What You Can Do

For IT Professionals and Security Teams:

For General Users:

The window between when attackers discover a vulnerability and when companies can patch it is one of the most dangerous periods in cybersecurity.

Organizations should prioritize addressing this issue quickly, as the active exploitation timeline means attackers are actively targeting vulnerable systems right now.

📎 This is original ITVedas reporting. This story was inspired by coverage from source. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters →