Article

    Cyber News / Article / A Vulnerability in VeloCloud Orchestrator (VCO) On-Prem Could Allow for Remote Code Execution

    A Vulnerability in VeloCloud Orchestrator (VCO) On-Prem Could Allow for Remote Code Execution
    -2026-07-28

    A Vulnerability in VeloCloud Orchestrator (VCO) On-Prem Could Allow for Remote Code Execution

    A vulnerability has been discovered in VeloCloud Orchestrator (VCO) On-Prem that could allow for remote code execution. VeloCloud Orchestrator is a centralized management platform used to configure, provision, monitor, and troubleshoot software-defined wide area networks (SD-WAN) and SASE components across enterprise edges and gateways. Successful exploitation of this vulnerability may allow a remote attacker to access privileged internal functionality, execute commands, and impact the VCO host. Depending on the privileges associated with the service account, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Services whose accounts are configured to have less rights on the system could be less impacted than those who operate with administrative user rights.

    The vendor reports that this vulnerability is actively being exploited. The following IP addresses have been observed conducting attacks:

    A vulnerability has been discovered in VeloCloud Orchestrator (VCO) On-Prem that could allow for remote code execution. Details of the vulnerability are as follows:

    Tactic:Initial Access (TA0001)

    Technique:Exploit Public-Facing Application (T1190)

    Successful exploitation of this vulnerability may allow a remote attacker to access privileged internal functionality, execute commands, and impact the VCO host. Depending on the privileges associated with the service account, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Services whose accounts are configured to have less rights on the system could be less impacted than those who operate with administrative user rights.

    We recommend the following actions be taken:

    Copyright©2026 Center for Internet Security®

    Original source