Download Privacy Needle App

Type to search

Cybersecurity

Critical VeloCloud Orchestrator Vulnerability Actively Exploited

Share

Attackers are actively exploiting a critical vulnerability in on-premises VeloCloud Orchestrator (VCO) servers, according to Arista. The flaw, tracked as CVE-2026-93952, carries a maximum CVSS score of 10.0.

The vulnerability allows a remote, unauthenticated attacker to escalate privileges within internal functions and impact the VCO host. A successful exploitation could lead to the compromise of the orchestrator, the data it manages, and the VeloCloud Edge devices within the SD-WAN network.

Affected Deployments

The risk is specifically tied to how VeloCloud Edges authenticate to the orchestrator. Arista has stated that an orchestrator is exposed if certificate-based authentication from the VeloCloud Edge to the VCO is configured. This includes environments using the ‘Certificate Acquire’ or ‘Certificate Required’ modes.

To exploit the flaw, an attacker requires network access to the VCO web interface and the public portion of an Edge’s authentication certificate. This differs from a previous vulnerability discovered in July, which affected all configurations by default.

Patch Availability and Mitigation

As of 22 September 2026, Arista has released fixed versions for the 5.2 and 6.4 release trains. Organisations on these trains should update to the following versions or later:

  • 5.2 release train: 5.2.3.15
  • 6.4 release train: 6.4.2.8

Critical updates are not yet available for the 6.1 and 7.0 release trains. Arista has noted that fixes for these supported trains are forthcoming. The company has already patched the Hosted and Dedicated versions of VCO.

For organisations unable to upgrade immediately, Arista recommends limiting access to the VCO web interface to trusted administrative networks only. Security teams should also monitor the VCO for access from known malicious IP addresses and watch for unexpected outbound network traffic from the host.

Signs of Compromise

Arista has cautioned that there is no single indicator to prove a VCO has been compromised through this specific flaw. However, administrators should review web access logs for unusual URL paths, encoded characters, or high request rates. Specific technical indicators to monitor include:

  • Files: /usr/local/sbin/.vcnode.js, /usr/local/sbin/vc-sysmond, or /etc/systemd/system/vc-sysmon.service
  • MD5 hash (vc-sysmond): dc78e206eaeadec59fc5801fe4556bd0
  • HTTP header in nginx logs: x-vc-opt
  • Known malicious IPs: 142.93.149.77 and 104.248.126.159

If any of these indicators are identified, Arista advises preserving the state of the VCO and contacting their Technical Assistance Centre (TAC) immediately. Post-upgrade incident response, including rotating credentials and reviewing administrator activity, is also recommended.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.