<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:arista_networks:velocloud_orchestrator:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aarista_networksvelocloud_orchestrator/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 22 Sep 2026 19:48:05 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aarista_networksvelocloud_orchestrator/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Active Exploitation of Arista VeloCloud Orchestrator</title><link>https://feed.craftedsignal.io/briefs/2026-09-arista-vco-vulnerability/</link><pubDate>Tue, 22 Sep 2026 19:48:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-arista-vco-vulnerability/</guid><description>Arista VeloCloud Orchestrator (VCO) On-Prem is vulnerable to CVE-2026-93952, which is confirmed to be under active exploitation in the wild.</description><content:encoded><![CDATA[<p>Arista Networks has released a security advisory concerning a critical vulnerability in VeloCloud Orchestrator (VCO) On-Prem identified as CVE-2026-93952. Multiple versions across the 5.2.x, 6.1.x, 6.4.x, and 7.0.x release branches are impacted. Security researchers and government reporting indicate that this vulnerability is currently being exploited in the wild, necessitating immediate attention from network administrators. Defending organizations running on-premises VeloCloud infrastructure should review the official Arista Security Advisory 0183 to identify the required patches or mitigation steps and prioritize deployment to prevent unauthorized access or compromise of the orchestrator platform.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-93952 on the VeloCloud Orchestrator allows unauthenticated attackers to gain unauthorized access or control over the target system. Given its role as a centralized management plane for SD-WAN infrastructure, a compromise could result in widespread network visibility loss, traffic interception, or the ability to reconfigure edge devices managed by the orchestrator.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Prioritize the immediate review and application of security patches provided in Arista Security Advisory 0183 for all affected versions of VeloCloud Orchestrator (VCO) On-Prem.</li>
<li>Audit firewall configurations to ensure that the VeloCloud Orchestrator management interface is not exposed to the public internet.</li>
<li>Monitor system logs and process activity on the VCO platform for signs of unauthorized access, particularly around the time of the advisory publication.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>vulnerability</category><category>network-security</category></item></channel></rss>