BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Critical VeloCloud Orchestrator flaw actively exploited

Critical Arista VCO flaw actively exploited, allows remote compromise of orchestrator and Edge devices.

  • Arista disclosed a critical flaw (CVE-2026-93952) in on-premises VeloCloud Orchestrator (VCO) actively exploited as of September 22.
  • The vulnerability, with a CVSS 3.1 score of 10.0, allows remote attackers to compromise the orchestrator and its managed Edge devices without authentication.
  • Only deployments using certificate-based authentication for Edge devices are exposed; fixed releases are available for some trains but not yet for 6.1 and 7.0.

Attackers are actively exploiting a critical flaw in on-premises Arista VeloCloud Orchestrator (VCO), the server managing Edge devices in SD-WAN deployments, the company disclosed on September 22.

- Advertisement -

The vulnerability, tracked as CVE-2026-93952, allows remote attackers without login credentials to elevate privileges and compromise the VCO host.

Arista gave the flaw a CVSS 3.1 score of 10.0 and stated it “was discovered externally and is known to be actively exploited.”

Consequently, a successful attack could compromise the orchestrator, managed data, and even the Edge devices it controls.

Only deployments configured with certificate-based authentication for Edge devices are exposed, according to Arista.

- Advertisement -

Fixed releases are available for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains.

Arista has already patched its Hosted and Dedicated VCO versions, and customers on unsupported trains can contact TAC about upgrade options.

The affected releases include those that previously fixed a different VCO flaw, which Arista reported as exploited in July.

Until a patch is applied, Arista recommends limiting access to the VCO web interface, monitoring for malicious activity, and reviewing recent administrator actions.

Specific indicators of compromise include the file /usr/local/sbin/.vcnode.js and the IP address 142.93.149[.]77, among others listed in the security advisory.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Tigress Financial Hikes Google Stock Target to $485

Google stock (NASDAQ: GOOG) opened at $350 Tuesday after a 2.3% rise from $340...

Circle sells Binance $100M in shares, deepens USDC deal

Circle sold Binance 1,237,011 Class A shares at $80.84 each, raising $100 million in...

Bitcoin Rally Has 2-4 Weeks Left, Says Analyst Willy Woo

Bitcoin surged to an eight-month high on Tuesday, though altcoins like Dogecoin, Sui, XRP,...

Solstice CEO: Deeper liquidity tames crypto volatility

Solstice CEO Ben Nadareski says deeper liquidity is reducing extreme boom-and-bust cycles in cryptoBitcoin's...

Mac Malware Hijacks Meta Muse, Security Researcher Warns

Security researcher Patrick Wardle disclosed a vulnerability in Meta's new Muse AI assistant for...

Must Read

This is How to Buy and Sell Bitcoin

Now more than ever, there are a variety of ways to enter and exit the crypto market. While this is good, the availability of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading