2026-09-23 · view entry permalink →
CVE-2026-93952, Arista VeloCloud Orchestrator: actively exploited, two release trains still have no fix
CVE-2026-93952 (CVSS 3.1: 10.0, CVSS 4.0: 9.5, CWE-20 improper input validation) affects on-premises VeloCloud Orchestrator (VCO), the SD-WAN control-plane server that provisions and manages VeloCloud Edge devices. Arista states the flaw "may allow a remote attacker to access privileged internal functionality and impact the VCO host," compromising confidentiality, integrity and availability of the orchestrator and the data it manages, and that a compromised VCO may in turn give an attacker access to the Edge devices it manages. Exposure is configuration-dependent: only VCOs with certificate-based Edge-to-VCO authentication configured are affected. "VCO is exposed if certificate based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured. Access to the public portion of the VeloCloud Edge authentication certificate is required. A successful attack requires network access to the VCO web interface. VCO tenant or operator credentials are not required for this exposure" (Arista Networks, Security Advisory 0183, 2026-09-22). Affected release trains: 5.2 (5.2.3.15 and below), 6.1 (6.1.3.7 and below), 6.4 (6.4.2.7 and below), and 7.0 (7.0.0.2 and below). As of 2026-09-22, fixes exist only for the 5.2 release train (5.2.3.16+) and the 6.4 release train (6.4.2.8+); Arista states "releases in other release trains that fix this will be added over time" (Arista Networks, Security Advisory 0183, 2026-09-22), the 6.1.x and 7.0.x trains have no fix yet, with no committed date. Arista's Hosted and Dedicated VCO offerings were already patched. "This issue was discovered externally and is known to be actively exploited" (Arista Networks, Security Advisory 0183, 2026-09-22); Arista does not disclose when exploitation began or its scale. The affected release trains are the same ones Arista reported exploited via a separate, unrelated VCO command-injection flaw disclosed two months earlier: "the vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution" (The Hacker News, 2026-07-28, reporting on Arista Security Advisory 0144), that flaw was fixed across all four trains at the time (5.2.3.14+, 6.1.3.4+, 6.4.2.4+, 7.0.0.1+); this one leaves two open. VCO has now been targeted twice within roughly two months. CISA added CVE-2026-93952 to KEV the same day (CISA KEV, catalogue version 2026.09.22).
Detection concept: review VCO web-access logs for requests with unusual URL-like path components, encoded characters, references to local or internal services, or abnormally high request rates; monitor for unexpected outbound HTTP/HTTPS connections originating from the VCO host itself, since an orchestrator should not normally initiate outbound web requests; watch for privileged configuration or maintenance actions that do not correspond to known administrator activity. Hardening: restrict VCO web-interface access to trusted administrative networks. On unpatched 6.1.x/7.0.x deployments, evaluate whether PSK-based Edge authentication (Certificate Deactivated mode) can substitute for certificate-based authentication until a fix ships; Arista's advisory conditions exposure on certificate-based authentication being configured without specifying which of its two certificate modes, and The Hacker News notes Arista "did not say which of those modes meets that condition" (The Hacker News, 2026-09-22), so PSK mode's exemption follows from the advisory's own precondition rather than a vendor statement naming PSK mode directly. Triage: an orchestrator initiating outbound connections, or a newly-created scheduled or persistence-related configuration entry with no corresponding change-management record, is the discriminator from routine administrative traffic.
This issue was discovered externally and is known to be actively exploited.
VCO is exposed if certificate based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured. Access to the public portion of the VeloCloud Edge authentication certificate is required. A successful attack requires network access to the VCO web interface. VCO tenant or operator credentials are not required for this exposure.
Releases in other release trains that fix this will be added over time.