On-prem VeloCloud Orchestrator under attack, only some versions patched
Arista warns the actively exploited CVSS 10.0 VeloCloud Orchestrator flaw CVE-2026-93952 has patches for only some affected release trains.
Arista disclosed CVE-2026-93952, an improper input validation flaw rated CVSS 10.0 in on-premises VeloCloud Orchestrator (VCO) that is known to be actively exploited and gives attackers access to privileged internal functionality. Exploitation requires certificate-based Edge-to-VCO authentication to be configured, plus the Edge certificate public key and network access to the VCO web interface; no tenant or operator credentials are needed, and Qualys assesses it as likely a CSRF-style bypass. Patches exist only for VCO 5.2.3.16+ and 6.4.2.8+; the 6.1.x and 7.0.x trains remain unpatched. Arista shared IoCs including a suspicious vc-sysmond file, the x-vc-opt HTTP header, and two source IPs tied to exploitation.
- CVE-2026-93952 (CVSS 10.0) actively exploited in on-prem VeloCloud Orchestrator
- Exploit needs Edge certificate public key and web access, not tenant credentials
- Fixes only for 5.2.3 and 6.4.2 trains; 6.1.x and 7.0.x still vulnerable
- IoCs: vc-sysmond file, x-vc-opt header, two malicious source IPs
Vulnerabilities mentionedAll →
- CVE-2026-939529.5<1%Unauthenticated Input-Validation Flaw in VeloCloud Orchestrator (On-Prem)published · Arista (VeloCloud; formerly VMware/Broadcom) VeloCloud Orchestrator (VCO), on-premises KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-93952 | Unauthenticated Input-Validation Flaw in VeloCloud Orchestrator (On-Prem) An improper input validation flaw (CWE-20) in the on-premises VeloCloud Orchestrator (VCO) allows a remote, unauthenticated attacker to reach privileged internal functionality on the orchestrator host. Exploitation occurs over the network with no credentials or user interaction (attack complexity is high), and success compromises the confidentiality, integrity, and availability of the orchestrator and the data it manages; the CVSS 4.0 vector also flags high impact on subsequent systems, meaning the SD-WAN edges and sites the orchestrator controls are at risk. Affected deployments are customer-operated on-prem VCO installations, while the vendor-hosted (including Dedicated) VCO service was also impacted but has already been patched. No public proof of concept or in-the-wild exploitation has been reported, and the issue is not on CISA's KEV list. |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 5.2.3.15 | i said. The affected versions span four VCO release trains: 5.2.3.15 and earlier in the 5.2.x train, 6.1.3.7 and earlier in 6.1. |
| ipv4 | 5.2.3.16 | arlier in 7.0. x. Arista has released fixes in VCO versions 5.2.3.16 and later in the 5.2.3 train and 6.4.2.8 and later in the 6 |
| ipv4 | 6.1.3.7 | CO release trains: 5.2.3.15 and earlier in the 5.2.x train, 6.1.3.7 and earlier in 6.1.x, 6.4.2.7 and earlier in 6.4.x, and 7.0 |
| ipv4 | 6.4.2.7 | d earlier in the 5.2.x train, 6.1.3.7 and earlier in 6.1.x, 6.4.2.7 and earlier in 6.4.x, and 7.0.0.2 and earlier in 7.0. x. Ar |
| ipv4 | 6.4.2.8 | s in VCO versions 5.2.3.16 and later in the 5.2.3 train and 6.4.2.8 and later in the 6.4.2 train. Fixes for the others trains a |
| ipv4 | 7.0.0.2 | 3.7 and earlier in 6.1.x, 6.4.2.7 and earlier in 6.4.x, and 7.0.0.2 and earlier in 7.0. x. Arista has released fixes in VCO ver |
Full article586 words · extracted from csoonline.com · click to collapse
A flaw in VeloCloud Orchestrator enables attackers to access the platform organizations use to manage their VeloCloud SD-WAN subscriptions and the edge devices it controls.
Arista, which now owns the VeloCloud business, warned customers that a vulnerable configuration exists in on-premises VeloCloud Orchestrator deployments that remote attackers may abuse to access “privileged internal functionality” and impact the VSO host. The flaw also affected Arista’s Hosted and Dedicated VCO deployments, but the company has now patched them.
“This issue was discovered externally and is known to be actively exploited,” Arista said in its advisory, urging customers to upgrade to a patched release of VCO immediately — although fixes are currently available only for some of the affected versions.
Mayuresh Dani, security research manager, at Qualys Threat Research Unit, warned that unpatched versions remain “exposed to active exploitation and have only compensating controls as a protection.”
Arista said that organizations suspecting compromise should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible.
Andrew Costis, engineering manager of the adversary research team at AttackIQ, backs that advice. “Patching closes the door but doesn’t reverse what came through it. A compromised orchestrator can reach the Edge devices it manages, rotate credentials and validate device state across sites,” he said.
Exploitation limited to a configuration
Arista is tracking the flaw as CVE-2026-93952, an improper input validation issue with a critical CVSS rating of 10.0.
An attack will only work under certain conditions, though: A VCO deployment is exposed only if certificate-based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured, and the attacker has the public key of the VeloCloud Edge authentication certificate and also network access to the VCO web interface. Attackers do not need VCO tenant or operator credentials.
“Based on the information available, this is most certainly a cross-site request forgery (CSRF) vulnerability that allows threat actors to use an Edge certificate to bypass the front-end and forward the request to internal services, which inherently trusts this information,” Dani said.
The affected versions span four VCO release trains: 5.2.3.15 and earlier in the 5.2.x train, 6.1.3.7 and earlier in 6.1.x, 6.4.2.7 and earlier in 6.4.x, and 7.0.0.2 and earlier in 7.0. x.
Arista has released fixes in VCO versions 5.2.3.16 and later in the 5.2.3 train and 6.4.2.8 and later in the 6.4.2 train.
Fixes for the others trains are still to come.
What defenders can do
For organizations that cannot immediately upgrade, Arista recommends restricting access to the VCO web interface to trusted administrative networks and monitoring for suspicious activities including known malicious source IPs, unexpected outbound network activity, backdoor daemons and webshells, and unexpected admin changes.
“Because successful exploitation may compromise the orchestrator host and data managed by the orchestrator, operators should follow incident-response guidance appropriate for their deployment,” the company added.
The advisory also shared a few indicators of compromise, including a suspicious “vc-sysmond” file, the “x-vc-opt “ HTTP header and two source IP addresses associated with exploitation activity.
AttackIQ’s Costis said Arista’s advice underlined the need for continuous threat exposure management and adversarial exposure validation: “Knowing which orchestrators are reachable, and proving your access restrictions actually hold, is worth far more before an advisory like this lands than after.”
This is the second maximum-severity VeloCloud flaw that Arista has had to patch this year. The company patched another actively exploited bug in the platform in July.
This article first appeared on Network World.