Critical VeloCloud Orchestrator Vulnerability Actively Exploited
Share
Attackers are actively exploiting a critical vulnerability in on-premises VeloCloud Orchestrator (VCO) servers, according to Arista. The flaw, tracked as CVE-2026-93952, carries a maximum CVSS score of 10.0.
The vulnerability allows a remote, unauthenticated attacker to escalate privileges within internal functions and impact the VCO host. A successful exploitation could lead to the compromise of the orchestrator, the data it manages, and the VeloCloud Edge devices within the SD-WAN network.
Affected Deployments
The risk is specifically tied to how VeloCloud Edges authenticate to the orchestrator. Arista has stated that an orchestrator is exposed if certificate-based authentication from the VeloCloud Edge to the VCO is configured. This includes environments using the ‘Certificate Acquire’ or ‘Certificate Required’ modes.
To exploit the flaw, an attacker requires network access to the VCO web interface and the public portion of an Edge’s authentication certificate. This differs from a previous vulnerability discovered in July, which affected all configurations by default.
Patch Availability and Mitigation
As of 22 September 2026, Arista has released fixed versions for the 5.2 and 6.4 release trains. Organisations on these trains should update to the following versions or later:
- 5.2 release train: 5.2.3.15
- 6.4 release train: 6.4.2.8
Critical updates are not yet available for the 6.1 and 7.0 release trains. Arista has noted that fixes for these supported trains are forthcoming. The company has already patched the Hosted and Dedicated versions of VCO.
For organisations unable to upgrade immediately, Arista recommends limiting access to the VCO web interface to trusted administrative networks only. Security teams should also monitor the VCO for access from known malicious IP addresses and watch for unexpected outbound network traffic from the host.
Signs of Compromise
Arista has cautioned that there is no single indicator to prove a VCO has been compromised through this specific flaw. However, administrators should review web access logs for unusual URL paths, encoded characters, or high request rates. Specific technical indicators to monitor include:
- Files:
/usr/local/sbin/.vcnode.js,/usr/local/sbin/vc-sysmond, or/etc/systemd/system/vc-sysmon.service - MD5 hash (vc-sysmond):
dc78e206eaeadec59fc5801fe4556bd0 - HTTP header in nginx logs:
x-vc-opt - Known malicious IPs:
142.93.149.77and104.248.126.159
If any of these indicators are identified, Arista advises preserving the state of the VCO and contacting their Technical Assistance Centre (TAC) immediately. Post-upgrade incident response, including rotating credentials and reviewing administrator activity, is also recommended.




Leave a Reply