Arista Issues Urgent Patch for Critical VeloCloud Orchestrator Zero-Day
Share
Arista has released urgent security patches for its on-premises VeloCloud Orchestrator (VCO) to address a critical zero-day vulnerability that is currently being actively exploited.
The flaw, tracked as CVE-2026-93952, has been assigned a Common Vulnerability Scoring System (CVSS) score of 10, representing the highest level of severity. The vulnerability is described as an improper input validation issue that could allow remote attackers to gain access to privileged internal functionality within the system.
VCO is a centralised management tool used to configure, monitor, and orchestrate edge devices and traffic within Arista VeloCloud Software-Defined Wide Area Network (SD-WAN) deployments. Successful exploitation of this defect could impact the confidentiality, integrity, and availability of the orchestrator and the data it manages.
Vulnerability Details and Exposure
Arista confirmed that the issue was discovered externally and is known to be in active use by threat actors. The vulnerability specifically affects VeloCloud Orchestrator On-Prem deployments (formerly known as VeloCloud Orchestrator by Broadcom).
The company noted that the exposure occurs if certificate-based authentication from the VeloCloud Edge to the VCO is configured. A successful attack requires network access to the VCO web interface; notably, an attacker does not require any existing VCO tenant or operator credentials to exploit the flaw.
Arista stated that deployments which restrict access to the VCO web interface face a lower risk, but strongly urged all administrators to update to a fixed release immediately.
CISA Response and Remediation
The United States Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-93952 to its Known Exploited Vulnerabilities (KEV) catalogue. Following federal directives, government agencies have been given three days to implement the necessary patches.
To remediate the risk, Arista has released fixes in the following versions:
- Version 5.2.3.16 (for the 5.2.x train)
- Version 6.4.2.8 (for the 6.1.x train)
Patches for other software trains are expected to be released shortly. Because there are currently no definitive indicators of compromise (IoCs), Arista recommends that administrators review VCO web access logs, backend application logs, and system logs for any signs of suspicious activity.




Leave a Reply