Arista fixes critical VeloCloud Orchestrator flaw under active attack

Arista Networks has issued patches for a maximum-severity vulnerability in VeloCloud Orchestrator On-Prem deployments that is already being exploited in the wild. The flaw, tracked as CVE-2026-93952, stems from improper input validation and allows remote attackers to access privileged internal functions without credentials. The company has updated hosted versions and is rolling out fixes for older on-premises releases, while CISA has added the bug to its known exploited vulnerabilities catalog.
The vulnerability affects VCO On-Prem deployments where certificate-based authentication from VeloCloud Edge to Orchestrator is configured. Attackers require network access to the VCO web interface but no credentials, making exploitation straightforward. Arista has already patched hosted versions running 5.2.3.16+ and 6.4.2.8+, with fixes forthcoming for older on-prem releases.
This marks Arista's third actively exploited zero-day patched this year, following CVE-2026-7473 affecting EOS in May and CVE-2026-16812 affecting on-prem VCO in July. CISA added the flaw to its known exploited vulnerabilities catalog and gave federal agencies until September 25 to secure systems. Arista provided indicators of compromise including specific IP addresses to block and guidance to review nginx logs for suspicious headers.
This vulnerability could affect enterprises relying on VeloCloud SD-WAN management, potentially allowing attackers to access privileged internal functions without credentials. Organizations using on-prem VCO deployments may face operational disruption while applying patches, and those with limited security resources could be especially vulnerable. The active exploitation suggests threat actors are moving quickly, which may pressure IT teams to prioritize remediation alongside other security obligations.