Skip to content
Threat Feed
critical threat exploited

Active Exploitation of Arista VeloCloud Orchestrator

Arista VeloCloud Orchestrator (VCO) On-Prem is vulnerable to CVE-2026-93952, which is confirmed to be under active exploitation in the wild.

CVE search metadata

CVE search record: CVE-2026-93952. Severity: critical. CVSS: 10.0. KEV: no. Product: VeloCloud Orchestrator (VCO) On-Prem (5.2.0-5.2.3.15, 6.1.0-6.1.3.7, 6.4.0-6.4.2.7, 7.0.0-7.0.0.2). Brief: Active Exploitation of Arista VeloCloud Orchestrator. Brief link: https://feed.craftedsignal.io/briefs/2026-09-arista-vco-vulnerability/

Arista Networks has released a security advisory concerning a critical vulnerability in VeloCloud Orchestrator (VCO) On-Prem identified as CVE-2026-93952. Multiple versions across the 5.2.x, 6.1.x, 6.4.x, and 7.0.x release branches are impacted. Security researchers and government reporting indicate that this vulnerability is currently being exploited in the wild, necessitating immediate attention from network administrators. Defending organizations running on-premises VeloCloud infrastructure should review the official Arista Security Advisory 0183 to identify the required patches or mitigation steps and prioritize deployment to prevent unauthorized access or compromise of the orchestrator platform.

Impact

Successful exploitation of CVE-2026-93952 on the VeloCloud Orchestrator allows unauthenticated attackers to gain unauthorized access or control over the target system. Given its role as a centralized management plane for SD-WAN infrastructure, a compromise could result in widespread network visibility loss, traffic interception, or the ability to reconfigure edge devices managed by the orchestrator.

Recommendation

  • Prioritize the immediate review and application of security patches provided in Arista Security Advisory 0183 for all affected versions of VeloCloud Orchestrator (VCO) On-Prem.
  • Audit firewall configurations to ensure that the VeloCloud Orchestrator management interface is not exposed to the public internet.
  • Monitor system logs and process activity on the VCO platform for signs of unauthorized access, particularly around the time of the advisory publication.

Immediate actions

Patch affected VeloCloud Orchestrator instances according to Security Advisory 0183

IT Operations 24h

Mitigations

Isolate VCO management interfaces from public internet access

immediate Network Engineering

CVE-2026-93952