Exploited Arista VeloCloud Orchestrator Flaw Only Partly Patched
Attackers are exploiting CVSS 10.0 CVE-2026-93952 in some on-premises VeloCloud Orchestrator certificate-auth setups; only two release trains are patched.
On-premises Arista VeloCloud Orchestrator deployments that authenticate Edges with certificates are under active attack via CVE-2026-93952, a CVSS 10.0 improper-input-validation flaw. A remote attacker who can reach the VCO web interface and knows an Edge certificate's public key can reach privileged internal or host functions and compromise the orchestrator and managed Edges, without tenant or operator credentials or user interaction; CSO Online says Qualys views it as likely a CSRF-style bypass. Canada's Cyber Centre advisory AV26-947 (22 September 2026) lists affected builds 5.2.0–5.2.3.15, 6.1.0–6.1.3.7, 6.4.0–6.4.2.7, and 7.0.0–7.0.0.2 and directs administrators to Arista Security Advisory 0183. Fixes start at 5.2.3.16 and 6.4.2.8, while 6.1 and 7.0 remain unpatched; The Hacker News says Hosted and Dedicated VCO are already patched, and SecurityWeek says more trains are planned. CISA added the bug to its KEV catalog, with federal remediation due 25 September 2026. Sources disagree on indicators: The Hacker News cites vc-sysmond and IPs 142.93.149.77 and 104.248.126.159, CSO Online reports a suspicious vc-sysmond file, the x-vc-opt header, and two source IPs, and SecurityWeek says Arista reported no definitive IoCs. The Hacker News also lists CVE-2026-16812 with no details in any report.
- CVE-2026-93952 is a CVSS 10.0 improper-input-validation flaw in on-premises Arista VeloCloud Orchestrator, actively exploited when Edges use certificate authentication.
- Exploitation needs network access to the VCO web interface and the Edge certificate public key, not tenant or operator credentials.
- Canadian Centre for Cyber Security advisory AV26-947 (22 September 2026) lists affected ranges 5.2.0–5.2.3.15, 6.1.0–6.1.3.7, 6.4.0–6.4.2.7, and 7.0.0–7.0.0.2, and points to Arista Security Advisory 0183.
- Fixes exist from 5.2.3.16 and 6.4.2.8; 6.1 and 7.0 have no fix yet. The Hacker News says Hosted and Dedicated VCO are already patched, and SecurityWeek says more trains are planned.
- CISA added CVE-2026-93952 to the KEV catalog; BleepingComputer reports a federal remediation deadline of 25 September 2026.
- IoCs conflict: The Hacker News cites vc-sysmond and IPs 142.93.149.77 and 104.248.126.159; CSO Online adds the x-vc-opt header and two source IPs; SecurityWeek says Arista reported no definitive IoCs.
- The Hacker News also lists CVE-2026-16812, but no report describes that identifier.
- CSO Online says Qualys assesses the flaw as likely a CSRF-style bypass.
Coverage timelineoldest first · each row is one article
- · 4d agoNew CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
The Hacker News· 87
Attackers are exploiting a CVSS 10.0 flaw in on-premises Arista VeloCloud Orchestrator deployments that use certificate authentication.
- · 4d agoArista Networks security advisory (AV26-947)
Canadian Centre for Cyber Security· 76
Canada's Cyber Centre warns CVE-2026-93952 in Arista VeloCloud Orchestrator is being exploited in the wild.
- · 3d agoArista Urges Immediate Patching of Exploited VCO Zero-Day
SecurityWeek· 88
Vulnerabilities in this storyAll →
- CVE-2026-1681210.01%OS Command Injection in Arista VeloCloud Orchestrator On-Prempublished · Arista VeloCloud Orchestrator On-Prem KEV