---
schema: 1
kind: vulnerability
title: "CVE-2026-93952 — Arista VeloCloud Orchestrator: actively exploited, two release trains still have no fix"
headline: "Arista confirms exploitation of an SD-WAN orchestrator flaw that has no patch for two of its four release trains"
summary: >
  Arista's on-premises VeloCloud Orchestrator (CVSS 10.0/9.5) is under
  active exploitation via a flaw reachable from the VCO web interface on
  deployments using certificate-based Edge authentication, requiring no VCO
  credentials. Fixes exist only for the 5.2 and 6.4 trains; 6.1.x and 7.0.x
  remain unpatched as of 2026-09-22 — the same trains Arista already
  reported exploited via a separate flaw in July 2026.
discovered_at: "2026-09-23T04:41:00Z"
updated_at: null
event_date: "2026-09-22"
run_id: 2026-09-23T0405Z-intel
priority: critical
immediate_action:
  title: "Patch or isolate every on-prem VeloCloud Orchestrator now — two release trains have no fix"
  action: >
    Arista confirms active exploitation. Deployments on the 5.2 or 6.4
    trains must upgrade to 5.2.3.16+ / 6.4.2.8+ immediately. Deployments on
    the unpatched 6.1.x or 7.0.x trains must restrict VCO web-interface
    access to trusted administrative networks now, and where feasible switch
    Edge authentication from certificate-based to PSK mode (Certificate
    Deactivated mode), since the flaw requires certificate-based
    authentication, until a fix ships.
tags: [vulnerabilities, rce, actively-exploited, cisa-kev, no-patch, default-config]
regions: [global]
sectors: [public-sector]
entities: ["product:arista-velocloud-orchestrator-on-prem"]
techniques: [T1190]
affected_products: ["Arista VeloCloud Orchestrator (VCO) On-Prem"]
cves:
  - id: CVE-2026-93952
    cvss: "10.0 (CVSS3.1) / 9.5 (CVSS4.0)"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, no-patch]
    affected: "5.2 release train 5.2.3.15 and below; 6.1 release train 6.1.3.7 and below (no fix yet); 6.4 release train 6.4.2.7 and below; 7.0 release train 7.0.0.2 and below (no fix yet) — on-prem VCO with certificate-based Edge authentication configured"
    fixed: "5.2.3.16+ (5.2.x train) and 6.4.2.8+ (6.4.x train) only; 6.1.x and 7.0.x trains have no fix as of 2026-09-22"
sources:
  - url: "https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183"
    publisher: "Arista Networks (Security Advisory 0183)"
    date: "2026-09-22"
    role: primary
  - url: "https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html"
    publisher: "The Hacker News"
    date: "2026-09-22"
    role: corroborating
  - url: "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0385"
    publisher: "NCSC-NL (NCSC-2026-0385)"
    date: "2026-09-22"
    role: corroborating
  - url: "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
    publisher: "CISA KEV"
    date: "2026-09-22"
    role: corroborating
  - url: "https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html"
    publisher: "The Hacker News"
    date: "2026-07-28"
    role: corroborating
closed_sources: []
evidence:
  - quote: "This issue was discovered externally and is known to be actively exploited."
    publisher: "Arista Networks (Security Advisory 0183)"
    source_url: "https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183"
  - quote: "VCO is exposed if certificate based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured. Access to the public portion of the VeloCloud Edge authentication certificate is required. A successful attack requires network access to the VCO web interface. VCO tenant or operator credentials are not required for this exposure."
    publisher: "Arista Networks (Security Advisory 0183)"
    source_url: "https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183"
  - quote: "Releases in other release trains that fix this will be added over time."
    publisher: "Arista Networks (Security Advisory 0183)"
    source_url: "https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183"
verification: multi-source
sourcing_note: null
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 1
watchlist_hit: false
actions:
  - "Upgrade every on-prem VeloCloud Orchestrator on the 5.2.x or 6.4.x train to 5.2.3.16+ / 6.4.2.8+ now."
  - "On the unpatched 6.1.x/7.0.x trains, restrict VCO web-interface access to trusted administrative networks now — no fix exists yet."
updates: []
migrated_from: null
---

CVE-2026-93952 (CVSS 3.1: 10.0, CVSS 4.0: 9.5, CWE-20 improper input validation) affects on-premises VeloCloud Orchestrator (VCO), the SD-WAN control-plane server that provisions and manages VeloCloud Edge devices. Arista states the flaw "may allow a remote attacker to access privileged internal functionality and impact the VCO host," compromising confidentiality, integrity and availability of the orchestrator and the data it manages — and that a compromised VCO may in turn give an attacker access to the Edge devices it manages. Exposure is configuration-dependent: only VCOs with certificate-based Edge-to-VCO authentication configured are affected. "VCO is exposed if certificate based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured. Access to the public portion of the VeloCloud Edge authentication certificate is required. A successful attack requires network access to the VCO web interface. VCO tenant or operator credentials are not required for this exposure" ([Arista Networks, Security Advisory 0183, 2026-09-22](https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183)). Affected release trains: 5.2 (5.2.3.15 and below), 6.1 (6.1.3.7 and below), 6.4 (6.4.2.7 and below), and 7.0 (7.0.0.2 and below). As of 2026-09-22, fixes exist only for the 5.2 release train (5.2.3.16+) and the 6.4 release train (6.4.2.8+); Arista states "releases in other release trains that fix this will be added over time" ([Arista Networks, Security Advisory 0183, 2026-09-22](https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183)) — the 6.1.x and 7.0.x trains have no fix yet, with no committed date. Arista's Hosted and Dedicated VCO offerings were already patched. "This issue was discovered externally and is known to be actively exploited" ([Arista Networks, Security Advisory 0183, 2026-09-22](https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183)); Arista does not disclose when exploitation began or its scale. The affected release trains are the same ones Arista reported exploited via a separate, unrelated VCO command-injection flaw disclosed two months earlier: "the vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution" ([The Hacker News, 2026-07-28](https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html), reporting on Arista Security Advisory 0144) — that flaw was fixed across all four trains at the time (5.2.3.14+, 6.1.3.4+, 6.4.2.4+, 7.0.0.1+); this one leaves two open. VCO has now been targeted twice within roughly two months. CISA added CVE-2026-93952 to KEV the same day ([CISA KEV, catalogue version 2026.09.22](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)).

Detection concept: review VCO web-access logs for requests with unusual URL-like path components, encoded characters, references to local or internal services, or abnormally high request rates; monitor for unexpected outbound HTTP/HTTPS connections originating from the VCO host itself, since an orchestrator should not normally initiate outbound web requests; watch for privileged configuration or maintenance actions that do not correspond to known administrator activity. Hardening: restrict VCO web-interface access to trusted administrative networks. On unpatched 6.1.x/7.0.x deployments, evaluate whether PSK-based Edge authentication (Certificate Deactivated mode) can substitute for certificate-based authentication until a fix ships — Arista's advisory conditions exposure on certificate-based authentication being configured without specifying which of its two certificate modes, and The Hacker News notes Arista "did not say which of those modes meets that condition" ([The Hacker News, 2026-09-22](https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html)), so PSK mode's exemption follows from the advisory's own precondition rather than a vendor statement naming PSK mode directly. **Triage:** an orchestrator initiating outbound connections, or a newly-created scheduled or persistence-related configuration entry with no corresponding change-management record, is the discriminator from routine administrative traffic.

**Defender takeaway:** on the 6.1.x/7.0.x trains there is no patch to apply — network isolation and, where feasible, switching away from certificate-based Edge authentication are the only controls until Arista ships a fix.
