Arista Urges Immediate Patching of Exploited VCO Zero-Day
Arista patched actively exploited VeloCloud Orchestrator zero-day CVE-2026-93952, now listed in CISA's KEV catalog.
Arista released urgent patches for CVE-2026-93952, a CVSS 10 improper-input-validation zero-day in on-premises VeloCloud Orchestrator that can let remote attackers reach privileged internal functions. The company says the externally discovered flaw is actively exploited, requires network access to the VCO web interface and the public edge authentication certificate, and does not need tenant or operator credentials. Fixes are available in versions 5.2.3.16 and 6.4.2.8. CISA added the bug to the Known Exploited Vulnerabilities catalog and gave federal agencies three days to patch; Arista says there are no definitive indicators of compromise.