{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aarista_networksvelocloud_orchestrator/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:arista_networks:velocloud_orchestrator:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-93952"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VeloCloud Orchestrator (VCO) On-Prem (5.2.0-5.2.3.15, 6.1.0-6.1.3.7, 6.4.0-6.4.2.7, 7.0.0-7.0.0.2)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","network-security"],"_cs_type":"threat","_cs_vendors":["Arista Networks"],"content_html":"\u003cp\u003eArista Networks has released a security advisory concerning a critical vulnerability in VeloCloud Orchestrator (VCO) On-Prem identified as CVE-2026-93952. Multiple versions across the 5.2.x, 6.1.x, 6.4.x, and 7.0.x release branches are impacted. Security researchers and government reporting indicate that this vulnerability is currently being exploited in the wild, necessitating immediate attention from network administrators. Defending organizations running on-premises VeloCloud infrastructure should review the official Arista Security Advisory 0183 to identify the required patches or mitigation steps and prioritize deployment to prevent unauthorized access or compromise of the orchestrator platform.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-93952 on the VeloCloud Orchestrator allows unauthenticated attackers to gain unauthorized access or control over the target system. Given its role as a centralized management plane for SD-WAN infrastructure, a compromise could result in widespread network visibility loss, traffic interception, or the ability to reconfigure edge devices managed by the orchestrator.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize the immediate review and application of security patches provided in Arista Security Advisory 0183 for all affected versions of VeloCloud Orchestrator (VCO) On-Prem.\u003c/li\u003e\n\u003cli\u003eAudit firewall configurations to ensure that the VeloCloud Orchestrator management interface is not exposed to the public internet.\u003c/li\u003e\n\u003cli\u003eMonitor system logs and process activity on the VCO platform for signs of unauthorized access, particularly around the time of the advisory publication.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T19:48:05Z","date_published":"2026-09-22T19:48:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-arista-vco-vulnerability/","summary":"Arista VeloCloud Orchestrator (VCO) On-Prem is vulnerable to CVE-2026-93952, which is confirmed to be under active exploitation in the wild.","title":"Active Exploitation of Arista VeloCloud Orchestrator","url":"https://feed.craftedsignal.io/briefs/2026-09-arista-vco-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:arista_networks:velocloud_orchestrator:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}