An improper input validation flaw (CWE-20) in the on-premises VeloCloud Orchestrator (VCO) allows a remote, unauthenticated attacker to reach privileged internal functionality on the orchestrator host. Exploitation occurs over the network with no credentials or user interaction (attack complexity is high), and success compromises the confidentiality, integrity, and availability of the orchestrator and the data it manages; the CVSS 4.0 vector also flags high impact on subsequent systems, meaning the SD-WAN edges and sites the orchestrator controls are at risk. Affected deployments are customer-operated on-prem VCO installations, while the vendor-hosted (including Dedicated) VCO service was also impacted but has already been patched. No public proof of concept or in-the-wild exploitation has been reported, and the issue is not on CISA's KEV list.
What to do: Update on-prem VCO to the fixed release specified in the Arista/Broadcom security advisory as soon as possible. Until patched, remove internet exposure by placing the orchestrator behind a VPN or IP allowlist, and audit logs for unauthenticated or anomalous API requests. Confirm hosted/Dedicated tenancies are on the current patched build and review managed edge devices for unauthorized configuration changes.
Arista (VeloCloud) VeloCloud Orchestrator — Hosted and Dedicated
Impacted, but vendor-hosted instances have already been patched
Estimated exposure
niche≈ several hundred internet-exposed on-prem VCO instances (order 10^2–10^3 total on-prem installs), each managing many SD-WAN edge devices — Most VeloCloud customers use the vendor-hosted orchestrator, and public internet scans typically show only a few hundred exposed VCO management portals, so the at-risk population is small in count but each instance is a critical control…
Description
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.
CISA Known Exploited Vulnerability
Affected
Arista VeloCloud Orchestrator
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Arista patches critical zero-day (CVE-2026-93952) in VeloCloud Orchestrator being actively exploited, allowing unauthenticated access to privileged host functions.
Arista Networks has patched CVE-2026-93952, a critical zero-day in VeloCloud Orchestrator (VCO) On-Prem deployments. The actively exploited flaw allows remote attackers to access privileged host functionality without user interaction or privileged credentials. CISA has added the CVE to its KEV catalog, mandating federal agency remediation by September 25, 2026.
CISA adds four actively exploited zero-days to KEV, forcing immediate patching of critical flaws in Check Point, Arista, and F5 systems.
CISA has added four actively exploited zero-day vulnerabilities to its KEV catalog, forcing US federal agencies to patch by September 25. The list includes critical flaws in Check Point Security Management (CVE-2026-93616) and Security Gateway (CVE-2026-85102), alongside zero-days in Arista VeloCloud Orchestrator (CVE-2026-93952) and F5 BIG-IP APM (CVE-2026-94127). Check Point confirmed exploitation against Management Servers and Spark firewalls globally.
Arista patched actively exploited VeloCloud Orchestrator zero-day CVE-2026-93952, now listed in CISA's KEV catalog.
Arista released urgent patches for CVE-2026-93952, a CVSS 10 improper-input-validation zero-day in on-premises VeloCloud Orchestrator that can let remote attackers reach privileged internal functions. The company says the externally discovered flaw is actively exploited, requires network access to the VCO web interface and the public edge authentication certificate, and does not need tenant or operator credentials. Fixes are available in versions 5.2.3.16 and 6.4.2.8. CISA added the bug to the Known Exploited Vulnerabilities catalog and gave federal agencies three days to patch; Arista says there are no definitive indicators of compromise.
Attackers are exploiting a CVSS 10.0 flaw in on-premises Arista VeloCloud Orchestrator deployments that use certificate authentication.
Arista said attackers are exploiting CVE-2026-93952, a CVSS 10.0 flaw in on-premises VeloCloud Orchestrator when Edges authenticate with certificates. An unauthenticated remote attacker who can reach the VCO web interface and knows the public part of an Edge certificate can invoke internal functions and compromise the orchestrator and managed Edge devices. Fixes are available for the 5.2 train from 5.2.3.16 and the 6.4 train from 6.4.2.8; 6.1 and 7.0 have no fix yet. Hosted and Dedicated VCO are already patched, and Arista published indicators including vc-sysmond and IPs 142.93.149.77 and 104.248.126.159.
CISA added four actively exploited Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its KEV catalog, with federal fixes due September 25.
CISA added CVE-2026-85102 (Check Point VPN certificate validation bypass), CVE-2026-93616 (Check Point Security Management Server path traversal), CVE-2026-93952 (Arista VeloCloud Orchestrator input validation), and CVE-2026-94127 (F5 BIG-IP APM heap buffer overflow) to the KEV catalog. Check Point stated CVE-2026-93616 is exploited in the wild with a handful of customers already attacked, and F5 confirmed exploitation of CVE-2026-94127 against APM OAuth Authorization Server configurations. Federal agencies must remediate by September 25, 2026 under BOD 22-01. Check Point has shipped LivePatch/Jumbo Hotfixes and an R82.20 Security Hotfix, plus IOCs for detection.
CISA added four actively exploited Check Point, Arista VeloCloud, and F5 BIG-IP flaws to the KEV catalog.
On 2026-09-22, CISA added four vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. They are CVE-2026-85102 (Check Point improper certificate validation), CVE-2026-93616 (Check Point path traversal), CVE-2026-93952 (Arista VeloCloud Orchestrator improper input validation), and CVE-2026-94127 (F5 BIG-IP APM heap-based buffer overflow). Binding Operational Directive 26-04 requires federal civilian agencies to prioritize remediation of high-risk KEV entries on exposed assets. CISA encourages all organizations to remediate these cataloged flaws quickly.
Arista warns the actively exploited CVSS 10.0 VeloCloud Orchestrator flaw CVE-2026-93952 has patches for only some affected release trains.
Arista disclosed CVE-2026-93952, an improper input validation flaw rated CVSS 10.0 in on-premises VeloCloud Orchestrator (VCO) that is known to be actively exploited and gives attackers access to privileged internal functionality. Exploitation requires certificate-based Edge-to-VCO authentication to be configured, plus the Edge certificate public key and network access to the VCO web interface; no tenant or operator credentials are needed, and Qualys assesses it as likely a CSRF-style bypass. Patches exist only for VCO 5.2.3.16+ and 6.4.2.8+; the 6.1.x and 7.0.x trains remain unpatched. Arista shared IoCs including a suspicious vc-sysmond file, the x-vc-opt HTTP header, and two source IPs tied to exploitation.
Canada's Cyber Centre warns CVE-2026-93952 in Arista VeloCloud Orchestrator is being exploited in the wild.
The Canadian Centre for Cyber Security issued AV26-947 on 22 September 2026 for Arista VeloCloud Orchestrator. Affected on-prem ranges are 5.2.0 through 5.2.3.15, 6.1.0 through 6.1.3.7, 6.4.0 through 6.4.2.7, and 7.0.0 through 7.0.0.2. Open-source reporting indicates CVE-2026-93952 is being exploited in the wild. Administrators are urged to review Arista Security Advisory 0183 and apply updates.