Arista urges immediate patching of exploited VCO zero-day
Summary
Arista has urged immediate action to patch a critical zero-day vulnerability, tracked as CVE-2026-93952, that affects specific on-premises VeloCloud Orchestrator release trains. The vulnerability poses risks for orchestrators that authenticate Edge devices using certificates, although hosted and dedicated VeloCloud Orchestrator versions have already received patches. Arista has made fixes available for the affected 5.2 and 6.4 trains, but noted that solutions for some versions 6.1 and 7.0 have not yet been released.
Analysis
Arista: Arista Networks develops networking products and software, including VeloCloud SD-WAN orchestration technology. In this incident, Arista disclosed active exploitation of a critical vulnerability in on-premises VeloCloud Orchestrator deployments and urged customers to apply available security updates. VeloCloud Orchestrator: VeloCloud Orchestrator is the centralized management platform used to configure and operate VeloCloud SD-WAN Edge devices. The on-premises product is affected by an actively exploited vulnerability that can allow an unauthenticated remote attacker to access privileged internal functionality and affect the host. Exposure: Arista indicated that the issue specifically affects orchestrators configured to authenticate Edge devices with certificates, while Hosted and Dedicated VeloCloud Orchestrator versions had already been patched. Patching: Arista has released fixes for the affected 5.2 and 6.4 trains, while fixes for some 6.1 and 7.0 releases were not yet available in the latest advisory. Vulnerability: The newly disclosed issue is tracked as CVE-2026-93952 and affects certain on-premises VeloCloud Orchestrator release trains.
Categories
tech
Related sources
- https://www.arista.com/en/support/advisories-notices
- https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html
- https://www.securityweek.com/critical-arista-velocloud-orchestrator-vulnerability-exploited-as-zero-day/
- https://windowsforum.com/news/cisa-kev-f5-check-point-and-arista-flaws-due-september-25.445484/
- https://www.it-boltwise.de/cvss-10-0-schwachstelle-in-velocloud-orchestrator-aktiv-ausgenutzt.html
- https://thehackernews.com/search/label/Vulnerability?updated-max=2026-09-18T16:31:00+05:30&max-results=20&start=960&by-date=false&m=1&hl=en_US
- https://malware.news/t/arista-networks-security-advisory-av26-947/125789
- https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183?tmpl=component&format=pdf
- https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/
- https://app.opencve.io/cve/?vendor=arista_networks
- https://feedly.com/cve/CVE-2026-93952
- https://protect.computer/news/2026-07-28-arista-velocloud-orchestrator-zero-day/
- https://www.hexnode.com/threat-watch/arista-velocloud-cve-2026-16812-exploited-sd-wan-zero-day-response-guide/
- https://www.hivepro.com/threat-advisory/critical-zero-day-hits-arista-velocloud-orchestrator
- https://feedly.com/cve/vendors/arista