- Arista disclosed a critical flaw (CVE-2026-93952) in on-premises VeloCloud Orchestrator (VCO) actively exploited as of September 22.
- The vulnerability, with a CVSS 3.1 score of 10.0, allows remote attackers to compromise the orchestrator and its managed Edge devices without authentication.
- Only deployments using certificate-based authentication for Edge devices are exposed; fixed releases are available for some trains but not yet for 6.1 and 7.0.
Attackers are actively exploiting a critical flaw in on-premises Arista VeloCloud Orchestrator (VCO), the server managing Edge devices in SD-WAN deployments, the company disclosed on September 22.
The vulnerability, tracked as CVE-2026-93952, allows remote attackers without login credentials to elevate privileges and compromise the VCO host.
Arista gave the flaw a CVSS 3.1 score of 10.0 and stated it “was discovered externally and is known to be actively exploited.”
Consequently, a successful attack could compromise the orchestrator, managed data, and even the Edge devices it controls.
Only deployments configured with certificate-based authentication for Edge devices are exposed, according to Arista.
Fixed releases are available for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains.
Arista has already patched its Hosted and Dedicated VCO versions, and customers on unsupported trains can contact TAC about upgrade options.
The affected releases include those that previously fixed a different VCO flaw, which Arista reported as exploited in July.
Until a patch is applied, Arista recommends limiting access to the VCO web interface, monitoring for malicious activity, and reviewing recent administrator actions.
Specific indicators of compromise include the file /usr/local/sbin/.vcnode.js and the IP address 142.93.149[.]77, among others listed in the security advisory.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
