On-prem VeloCloud Orchestrator under attack, only some versions patched
Arista warns the actively exploited CVSS 10.0 VeloCloud Orchestrator flaw CVE-2026-93952 has patches for only some affected release trains.
Arista disclosed CVE-2026-93952, an improper input validation flaw rated CVSS 10.0 in on-premises VeloCloud Orchestrator (VCO) that is known to be actively exploited and gives attackers access to privileged internal functionality. Exploitation requires certificate-based Edge-to-VCO authentication to be configured, plus the Edge certificate public key and network access to the VCO web interface; no tenant or operator credentials are needed, and Qualys assesses it as likely a CSRF-style bypass. Patches exist only for VCO 5.2.3.16+ and 6.4.2.8+; the 6.1.x and 7.0.x trains remain unpatched. Arista shared IoCs including a suspicious vc-sysmond file, the x-vc-opt HTTP header, and two source IPs tied to exploitation.