Arista VeloCloud Orchestrator Maximum Severity Flaw Exploited With No Available Workaround (CVE-2026-93952)
Scope: Arista VeloCloud Orchestrator (VCO) On-Prem Deployments
Severity: Red
Arista released emergency patches on September 22, 2026, for CVE-2026-93952, a maximum severity improper input validation vulnerability rated CVSS 10.0, after confirming active exploitation of the on-premises version of VeloCloud Orchestrator, the centralized platform administrators use to configure and monitor VeloCloud SD-WAN deployments and their connected Edge devices. The flaw allows a remote, unauthenticated attacker to reach privileged internal functionality that was never intended to be exposed externally, and Arista has stated plainly that the on-premises orchestrator is exposed by default with no configuration capable of removing that exposure entirely. Because a compromised orchestrator can extend an attacker's reach to every VeloCloud Edge device it manages, the potential blast radius goes well beyond the orchestrator host itself. CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, alongside three other actively exploited edge and management-plane flaws from Check Point and F5, with a shared federal deadline of September 25, 2026. Arista has published two known malicious IP addresses associated with the attacks. Organizations running VCO On-Prem must upgrade to a remediated release immediately, restrict the VCO web interface to trusted administrative networks, and review web access and nginx logs for the published indicators, including the x-vc-opt HTTP header, as well as any unexpected outbound HTTP or HTTPS activity from the VCO host.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.