MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-23 · via BleepingComputer

Arista fixes critical VeloCloud Orchestrator flaw under active attack

Image via BleepingComputer
Image via BleepingComputer

Arista Networks has issued patches for a maximum-severity vulnerability in VeloCloud Orchestrator On-Prem deployments that is already being exploited in the wild. The flaw, tracked as CVE-2026-93952, stems from improper input validation and allows remote attackers to access privileged internal functions without credentials. The company has updated hosted versions and is rolling out fixes for older on-premises releases, while CISA has added the bug to its known exploited vulnerabilities catalog.

Expanded Detail

The vulnerability affects VCO On-Prem deployments where certificate-based authentication from VeloCloud Edge to Orchestrator is configured. Attackers require network access to the VCO web interface but no credentials, making exploitation straightforward. Arista has already patched hosted versions running 5.2.3.16+ and 6.4.2.8+, with fixes forthcoming for older on-prem releases.

This marks Arista's third actively exploited zero-day patched this year, following CVE-2026-7473 affecting EOS in May and CVE-2026-16812 affecting on-prem VCO in July. CISA added the flaw to its known exploited vulnerabilities catalog and gave federal agencies until September 25 to secure systems. Arista provided indicators of compromise including specific IP addresses to block and guidance to review nginx logs for suspicious headers.

Context

This vulnerability could affect enterprises relying on VeloCloud SD-WAN management, potentially allowing attackers to access privileged internal functions without credentials. Organizations using on-prem VCO deployments may face operational disruption while applying patches, and those with limited security resources could be especially vulnerable. The active exploitation suggests threat actors are moving quickly, which may pressure IT teams to prioritize remediation alongside other security obligations.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
F5 issues emergency patch for BIG-IP APM zero-day under active exploitation · Cybersecurity
Check Point rushes hotfix for critical management server flaw under active exploitation · Cybersecurity
D-Link flags unpatched critical flaw in legacy routers with public exploit · Cybersecurity
U.S. agencies face Thursday deadline to fix Zyxel switch bug under active attack · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Arista patches actively exploited VeloCloud Orchestrator zero-day.” Browse more stories.