Download Privacy Needle App

Type to search

Cybersecurity

Arista Issues Urgent Patch for Critical VeloCloud Orchestrator Zero-Day

Share

Arista has released urgent security patches for its on-premises VeloCloud Orchestrator (VCO) to address a critical zero-day vulnerability that is currently being actively exploited.

The flaw, tracked as CVE-2026-93952, has been assigned a Common Vulnerability Scoring System (CVSS) score of 10, representing the highest level of severity. The vulnerability is described as an improper input validation issue that could allow remote attackers to gain access to privileged internal functionality within the system.

VCO is a centralised management tool used to configure, monitor, and orchestrate edge devices and traffic within Arista VeloCloud Software-Defined Wide Area Network (SD-WAN) deployments. Successful exploitation of this defect could impact the confidentiality, integrity, and availability of the orchestrator and the data it manages.

Vulnerability Details and Exposure

Arista confirmed that the issue was discovered externally and is known to be in active use by threat actors. The vulnerability specifically affects VeloCloud Orchestrator On-Prem deployments (formerly known as VeloCloud Orchestrator by Broadcom).

The company noted that the exposure occurs if certificate-based authentication from the VeloCloud Edge to the VCO is configured. A successful attack requires network access to the VCO web interface; notably, an attacker does not require any existing VCO tenant or operator credentials to exploit the flaw.

Arista stated that deployments which restrict access to the VCO web interface face a lower risk, but strongly urged all administrators to update to a fixed release immediately.

CISA Response and Remediation

The United States Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-93952 to its Known Exploited Vulnerabilities (KEV) catalogue. Following federal directives, government agencies have been given three days to implement the necessary patches.

To remediate the risk, Arista has released fixes in the following versions:

  • Version 5.2.3.16 (for the 5.2.x train)
  • Version 6.4.2.8 (for the 6.1.x train)

Patches for other software trains are expected to be released shortly. Because there are currently no definitive indicators of compromise (IoCs), Arista recommends that administrators review VCO web access logs, backend application logs, and system logs for any signs of suspicious activity.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.