Back to all news
Cybersecurity 2 min read

Arista Issues Critical Patch for Actively Exploited VeloCloud Orchestrator Zero‑Day

Fiji businesses using SD‑WAN solutions must apply the update immediately to mitigate a high‑severity threat

Arista has released a patch for a zero‑day vulnerability in its VeloCloud Orchestrator that is already being exploited in the wild. The fix is critical for any organisation, including those in Fiji, that rely on VeloCloud for software‑defined networking.

What happened

Arista Networks announced that a zero‑day vulnerability in its VeloCloud Orchestrator (VCO) is being actively exploited. The company has released a patch to address the flaw, urging customers to apply it without delay.

Why it matters

The VCO is a central component of Arista’s SD‑WAN offering, managing traffic routing and security policies across distributed sites. An actively exploited vulnerability in such a core controller can allow attackers to gain unauthorized access to network management functions, potentially compromising data flow, disrupting services, or enabling further lateral movement within an organisation’s infrastructure.

What this means for Fiji businesses

Fiji enterprises that have adopted Arista’s SD‑WAN solutions, or that use any third‑party product built on the VeloCloud platform, are directly exposed to this risk. Even organisations that do not run VCO themselves may be affected if they connect to partners or suppliers that do, because compromised SD‑WAN controllers can become a conduit for broader network attacks.

What businesses should do now

  1. Identify VCO deployments – Verify whether your network architecture includes VeloCloud Orchestrator, either on‑premises or as a managed service.
  2. Apply the Arista patch immediately – Follow Arista’s official guidance to download and install the security update.
  3. Review access controls – Ensure that only authorised personnel have administrative access to the VCO console and that multi‑factor authentication is enforced.
  4. Monitor for indicators of compromise – Look for unusual login attempts, configuration changes, or traffic anomalies that could signal exploitation.
  5. Engage vendors and partners – If you rely on third‑party managed SD‑WAN services, confirm that they have applied the patch and request evidence of remediation.
  6. Update incident‑response playbooks – Incorporate this vulnerability into your cyber‑risk assessments and ensure response procedures cover potential SD‑WAN compromise.

Taking these steps will help Fiji businesses protect critical network infrastructure and maintain continuity of operations in the face of an actively exploited threat.

Independent evidence

Sources

3 sources

Aura Digital Fiji · Digital services

Need help applying this technology to your business?

Custom websites, ecommerce, business email, security, mobile apps and IT systems built for Fiji businesses.

Continue reading

Related intelligence

All news →