Arista patches actively exploited VeloCloud Orchestrator zero-day
Arista patches critical zero-day (CVE-2026-93952) in VeloCloud Orchestrator being actively exploited, allowing unauthenticated access to privileged host functions.
Arista Networks has patched CVE-2026-93952, a critical zero-day in VeloCloud Orchestrator (VCO) On-Prem deployments. The actively exploited flaw allows remote attackers to access privileged host functionality without user interaction or privileged credentials. CISA has added the CVE to its KEV catalog, mandating federal agency remediation by September 25, 2026.
- Arista patched actively exploited zero-day in VeloCloud Orchestrator (CVE-2026-93952).
- Max-severity flaw in certificate-based auth allows low-complexity remote access.
- CISA added CVE-2026-93952 to KEV catalog; agencies must remediate by Sept 25.
Vulnerabilities mentionedAll →
- CVE-2026-939529.5<1%Unauthenticated Input-Validation Flaw in VeloCloud Orchestrator (On-Prem)published · Arista (VeloCloud; formerly VMware/Broadcom) VeloCloud Orchestrator (VCO), on-premises KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-93952 | Unauthenticated Input-Validation Flaw in VeloCloud Orchestrator (On-Prem) An improper input validation flaw (CWE-20) in the on-premises VeloCloud Orchestrator (VCO) allows a remote, unauthenticated attacker to reach privileged internal functionality on the orchestrator host. Exploitation occurs over the network with no credentials or user interaction (attack complexity is high), and success compromises the confidentiality, integrity, and availability of the orchestrator and the data it manages; the CVSS 4.0 vector also flags high impact on subsequent systems, meaning the SD-WAN edges and sites the orchestrator controls are at risk. Affected deployments are customer-operated on-prem VCO installations, while the vendor-hosted (including Dedicated) VCO service was also impacted but has already been patched. No public proof of concept or in-the-wild exploitation has been reported, and the issue is not on CISA's KEV list. |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 5.2.3.16 | that it has already patched hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later and that it will also rel |
| ipv4 | 6.1.3.7 | ill also release security patches for VCO instances running 6.1.3.7 and below and 7.0.0.2 and below. The U.S. Cybersecurity and |
| ipv4 | 6.4.2.8 | ed hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later and that it will also release security patches for |
| ipv4 | 7.0.0.2 | ity patches for VCO instances running 6.1.3.7 and below and 7.0.0.2 and below. The U.S. Cybersecurity and Infrastructure Securi |
Full article498 words · extracted from bleepingcomputer.com · click to collapse

Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments.
VCO is a cloud-based centralized management platform that helps admins configure, monitor, and manage VeloCloud SD-WANs (Software-Defined Wide Area Networks) and associated edge devices.
Tracked as CVE-2026-93952, this maximum-severity flaw stems from an improper input validation weakness and affects VCO deployments where certificate-based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured.
Remote threat actors can exploit the vulnerability to access privileged internal VCO host functionality in low-complexity attacks that don't require privileges on the targeted system or user interaction.
"This issue was discovered externally and is known to be actively exploited," the company warned in a Tuesday advisory. "Access to the public portion of the VeloCloud Edge authentication certificate is required. A successful attack requires network access to the VCO web interface. VCO tenant or operator credentials are not required for this exposure."
Arista says that it has already patched hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later and that it will also release security patches for VCO instances running 6.1.3.7 and below and 7.0.0.2 and below.
The U.S. Cybersecurity and Infrastructure Security Agency has also added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog on Tuesday and ordered U.S. federal civilian executive branch agencies to secure their networks by Friday, September 25.
Indicators of compromise
While security patches are being deployed, admins should restrict access to the VCO web interface to administrative networks, review recent administrator activity for unusual changes, and monitor for connections from known malicious IP addresses.
Admins should review VCO web access logs for suspicious activity, such as requests containing encoded characters, unusual URL-like path components, references to local or internal services, or high request rates.
Arista also advised security teams to block the 142[.]93.149.77 and 104[.]248.126.159 IP addresses and review nginx logs for the x-vc-opt HTTP header, and said that unexpected outbound HTTP or HTTPS activity originating from the VCO host may also warrant further review.
"If compromise is suspected, operators should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible," it added, and advised customers to contact the Arista Networks Technical Assistance Center (TAC) if they need additional assistance.
Since the start of the year, Arista patched two other zero-day flaws (CVE-2026-7473 in May and CVE-2026-16812 in July) that were being actively exploited in attacks and affected Extensible Operating System (EOS) and on-premises VeloCloud Orchestrator deployments, respectively.
Arista Networks is a Fortune 500 company and one of the largest United States corporations by revenue, with more than 10,000 customers worldwide.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.