Arista Networks security advisory (AV26-947)
Canada's Cyber Centre warns CVE-2026-93952 in Arista VeloCloud Orchestrator is being exploited in the wild.
The Canadian Centre for Cyber Security issued AV26-947 on 22 September 2026 for Arista VeloCloud Orchestrator. Affected on-prem ranges are 5.2.0 through 5.2.3.15, 6.1.0 through 6.1.3.7, 6.4.0 through 6.4.2.7, and 7.0.0 through 7.0.0.2. Open-source reporting indicates CVE-2026-93952 is being exploited in the wild. Administrators are urged to review Arista Security Advisory 0183 and apply updates.