Arista Networks security advisory (AV26-947)
Canada's Cyber Centre warns CVE-2026-93952 in Arista VeloCloud Orchestrator is being exploited in the wild.
The Canadian Centre for Cyber Security issued AV26-947 on 22 September 2026 for Arista VeloCloud Orchestrator. Affected on-prem ranges are 5.2.0 through 5.2.3.15, 6.1.0 through 6.1.3.7, 6.4.0 through 6.4.2.7, and 7.0.0 through 7.0.0.2. Open-source reporting indicates CVE-2026-93952 is being exploited in the wild. Administrators are urged to review Arista Security Advisory 0183 and apply updates.
- CVE-2026-93952 affects on-prem VeloCloud Orchestrator 5.2, 6.1, 6.4, and 7.0.
- Open-source reporting says the vulnerability is exploited in the wild.
- The Cyber Centre points administrators to Arista advisory 0183.
Vulnerabilities mentionedAll →
- CVE-2026-939529.5<1%Unauthenticated Input-Validation Flaw in VeloCloud Orchestrator (On-Prem)published · Arista (VeloCloud; formerly VMware/Broadcom) VeloCloud Orchestrator (VCO), on-premises KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-93952 | Unauthenticated Input-Validation Flaw in VeloCloud Orchestrator (On-Prem) An improper input validation flaw (CWE-20) in the on-premises VeloCloud Orchestrator (VCO) allows a remote, unauthenticated attacker to reach privileged internal functionality on the orchestrator host. Exploitation occurs over the network with no credentials or user interaction (attack complexity is high), and success compromises the confidentiality, integrity, and availability of the orchestrator and the data it manages; the CVSS 4.0 vector also flags high impact on subsequent systems, meaning the SD-WAN edges and sites the orchestrator controls are at risk. Affected deployments are customer-operated on-prem VCO installations, while the vendor-hosted (including Dedicated) VCO service was also impacted but has already been patched. No public proof of concept or in-the-wild exploitation has been reported, and the issue is not on CISA's KEV list. |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 5.2.3.15 | uct: VeloCloud Orchestrator (VCO) On-Prem Versions 5.2.0 to 5.2.3.15 Versions 6.1.0 to 6.1.3.7 Versions 6.4.0 to 6.4.2.7 Version |
| ipv4 | 6.1.3.7 | (VCO) On-Prem Versions 5.2.0 to 5.2.3.15 Versions 6.1.0 to 6.1.3.7 Versions 6.4.0 to 6.4.2.7 Versions 7.0.0 to 7.0.0.2 Open-so |
| ipv4 | 6.4.2.7 | 2.0 to 5.2.3.15 Versions 6.1.0 to 6.1.3.7 Versions 6.4.0 to 6.4.2.7 Versions 7.0.0 to 7.0.0.2 Open-source reporting indicates t |
| ipv4 | 7.0.0.2 | .1.0 to 6.1.3.7 Versions 6.4.0 to 6.4.2.7 Versions 7.0.0 to 7.0.0.2 Open-source reporting indicates that CVE-2026-93952 is bein |
Full article84 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-947
Date: September 22, 2026
As of September 22, 2026, Arista Networks is affected by a vulnerability in the following product:
- VeloCloud Orchestrator (VCO) On-Prem
- Versions 5.2.0 to 5.2.3.15
- Versions 6.1.0 to 6.1.3.7
- Versions 6.4.0 to 6.4.2.7
- Versions 7.0.0 to 7.0.0.2
Open-source reporting indicates that CVE-2026-93952 is being exploited in the wild.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/arista-networks-security-advisory-av26-947