Arista Urges Immediate Patching of Exploited VCO Zero-Day
Arista patched actively exploited VeloCloud Orchestrator zero-day CVE-2026-93952, now listed in CISA's KEV catalog.
Arista released urgent patches for CVE-2026-93952, a CVSS 10 improper-input-validation zero-day in on-premises VeloCloud Orchestrator that can let remote attackers reach privileged internal functions. The company says the externally discovered flaw is actively exploited, requires network access to the VCO web interface and the public edge authentication certificate, and does not need tenant or operator credentials. Fixes are available in versions 5.2.3.16 and 6.4.2.8. CISA added the bug to the Known Exploited Vulnerabilities catalog and gave federal agencies three days to patch; Arista says there are no definitive indicators of compromise.
- CVE-2026-93952 is a CVSS 10 improper-input-validation flaw in on-prem VCO.
- Arista says the externally found bug is actively exploited and requires no credentials.
- Exposure needs edge certificate authentication and network access to the web interface.
- Fixes are VCO 5.2.3.16 and 6.4.2.8, with more trains planned.
- CISA added it to KEV and gave federal agencies three days to patch.
Vulnerabilities mentionedAll →
- CVE-2026-939529.5<1%Unauthenticated Input-Validation Flaw in VeloCloud Orchestrator (On-Prem)published · Arista (VeloCloud; formerly VMware/Broadcom) VeloCloud Orchestrator (VCO), on-premises KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-93952 | Unauthenticated Input-Validation Flaw in VeloCloud Orchestrator (On-Prem) An improper input validation flaw (CWE-20) in the on-premises VeloCloud Orchestrator (VCO) allows a remote, unauthenticated attacker to reach privileged internal functionality on the orchestrator host. Exploitation occurs over the network with no credentials or user interaction (attack complexity is high), and success compromises the confidentiality, integrity, and availability of the orchestrator and the data it manages; the CVSS 4.0 vector also flags high impact on subsequent systems, meaning the SD-WAN edges and sites the orchestrator controls are at risk. Affected deployments are customer-operated on-prem VCO installations, while the vendor-hosted (including Dedicated) VCO service was also impacted but has already been patched. No public proof of concept or in-the-wild exploitation has been reported, and the issue is not on CISA's KEV list. |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 5.2.3.16 | Orchestrator by Broadcom) and was resolved in VCO versions 5.2.3.16 and 6.4.2.8 in the 5.2.x and 6.1.x trains, respectively. Pa |
| ipv4 | 6.4.2.8 | by Broadcom) and was resolved in VCO versions 5.2.3.16 and 6.4.2.8 in the 5.2.x and 6.1.x trains, respectively. Patches for ot |
Full article329 words · extracted from securityweek.com · click to collapse
Networking solutions provider Arista has released urgent patches for a critical-severity vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments that has been exploited as a zero-day.
VCO is a centralized management tool for configuring, monitoring, and orchestrating edge devices, policies, and traffic in Arista VeloCloud SD-WAN.
The exploited zero-day, tracked as CVE-2026-93952 (CVSS score of 10), is described as an improper input validation issue that could allow remote attackers to access privileged internal functionality.
Successful exploitation of the security defect could impact the confidentiality, integrity, and availability of the orchestrator and the data it manages.
“This issue was discovered externally and is known to be actively exploited,” Arista warns.
According to the company, the bug affects only VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom) and was resolved in VCO versions 5.2.3.16 and 6.4.2.8 in the 5.2.x and 6.1.x trains, respectively. Patches for other trains will also be released.
Advertisement. Scroll to continue reading.
“VCO is exposed if certificate-based authentication from the VeloCloud Edge to VCO is configured. Access to the public portion of the VeloCloud Edge authentication certificate is required. A successful attack requires network access to the VCO web interface. VCO tenant or operator credentials are not required for this exposure,” the company notes.
Arista says that deployments that limit access to the VCO web interface have a lower risk of exposure, but urges updating to a fixed release.
The company noted that there are no definitive indicators of compromise (IoCs), recommending administrators review VCO web access logs, backend application logs, and system logs for suspicious activity.
CVE-2026-93952 was added to CISA’s Known Exploited Vulnerabilities (KEV) list on Tuesday. In line with BOD 26-04’s recommendations, federal agencies were given three days to patch it.
Related: Critical F5 BIG-IP APM Vulnerability Exploited as a Zero-Day
Related: Check Point Patches Exploited Management Server Zero-Day
Related: Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity
Related: Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard