{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/velocloud/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VeloCloud Orchestrator On-Prem"],"_cs_severities":["critical"],"_cs_tags":["rce","vulnerability","network","sd-wan","sase"],"_cs_type":"advisory","_cs_vendors":["VeloCloud"],"content_html":"\u003cp\u003eA critical vulnerability has been discovered in VeloCloud Orchestrator (VCO) On-Prem, a centralized management platform for software-defined wide area networks (SD-WAN) and SASE components. This flaw could allow a remote attacker to achieve remote code execution (RCE) on the VCO host. The vulnerability grants unauthorized access to privileged internal functionality, allowing the execution of arbitrary commands. This could lead to severe consequences, including the ability to install malicious programs, view, alter, or delete sensitive data, or create new user accounts with full administrative privileges. The specific impact on a system depends directly on the privilege level configured for the service account associated with the exploited VCO instance, making systems with administrative account privileges highly susceptible to complete compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eA remote attacker identifies a vulnerable VeloCloud Orchestrator (VCO) On-Prem instance exposed to the network.\u003c/li\u003e\n\u003cli\u003eThe attacker exploits the vulnerability to gain unauthorized access to privileged internal functionality within the VCO platform.\u003c/li\u003e\n\u003cli\u003eLeveraging this access, the attacker successfully executes arbitrary commands on the underlying VCO host.\u003c/li\u003e\n\u003cli\u003eDepending on the initial privileges obtained, the attacker may perform privilege escalation to gain higher-level system access.\u003c/li\u003e\n\u003cli\u003eThe attacker proceeds to impact the VCO host by installing programs, viewing, changing, or deleting sensitive data, or creating new accounts with full user rights.\u003c/li\u003e\n\u003cli\u003eWith control over the VCO, the attacker could potentially manipulate the managed SD-WAN and SASE components, affecting network operations and security.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability could lead to a complete compromise of the VeloCloud Orchestrator On-Prem host. An attacker could gain administrative control, allowing them to install arbitrary programs, modify or exfiltrate sensitive configuration data, delete critical files, and create new user accounts with full administrative rights. The extent of the damage is directly tied to the privileges of the exploited service account; systems running VCO with highly privileged accounts face the risk of total system takeover and potential disruption or manipulation of the entire SD-WAN and SASE infrastructure managed by the orchestrator.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch VeloCloud Orchestrator On-Prem immediately upon release of an official security update from VeloCloud to remediate the undisclosed vulnerability.\u003c/li\u003e\n\u003cli\u003eRestrict network access to VeloCloud Orchestrator (VCO) On-Prem instances, ensuring they are not directly exposed to the public internet unless absolutely necessary, to mitigate remote exploitation attempts.\u003c/li\u003e\n\u003cli\u003eImplement the principle of least privilege for all service accounts associated with VCO On-Prem components to limit the potential impact of successful exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T14:22:47Z","date_published":"2026-07-28T14:22:47Z","id":"https://feed.craftedsignal.io/briefs/2026-07-velocloud-rce/","summary":"A critical vulnerability has been identified in VeloCloud Orchestrator (VCO) On-Prem that allows for remote code execution, enabling a remote attacker to gain privileged access, execute arbitrary commands on the VCO host, and potentially install programs, modify or delete data, or create new user accounts with administrative rights, with impact severity depending on the service account privileges.","title":"Vulnerability in VeloCloud Orchestrator On-Prem Allows Remote Code Execution","url":"https://feed.craftedsignal.io/briefs/2026-07-velocloud-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - VeloCloud","version":"https://jsonfeed.org/version/1.1"}