Your WAN orchestrator is on the internet by design: VeloCloud's 10.0
CVE-2026-16812 is an unauthenticated command injection in the on-premises VeloCloud Orchestrator: CVSS 10.0, exploited before a patch existed, and in CISA's KEV catalogue the same day with three days to fix it. Arista's advisory says the console is exposed by default and that no configuration prevents that exposure; a few lines further down it recommends restricting access to the web interface to trusted administrative networks. Both are true, and the bad day is decided in the distance between them.