Arista patches actively exploited VeloCloud Orchestrator zero-day
Arista patches critical zero-day (CVE-2026-93952) in VeloCloud Orchestrator being actively exploited, allowing unauthenticated access to privileged host functions.
Arista Networks has patched CVE-2026-93952, a critical zero-day in VeloCloud Orchestrator (VCO) On-Prem deployments. The actively exploited flaw allows remote attackers to access privileged host functionality without user interaction or privileged credentials. CISA has added the CVE to its KEV catalog, mandating federal agency remediation by September 25, 2026.