Arista VeloCloud Orchestrator vulnerability

An Arista VeloCloud Orchestrator vulnerability (CVSS 10.0) lets attackers reach privileged functions with no credentials. Patch and hunt for backdoors now.

An Arista VeloCloud Orchestrator vulnerability, CVE-2026-93952 (CVSS 10.0), lets an attacker reach privileged internal functions on the on-premises controller for an entire SD-WAN fabric without any credentials at all. Arista confirmed active exploitation and shipped a patch on September 22. This is the second maximum-severity CVE in this exact product line in 2026, after the command-injection flaw DIESEC covered on July 30.

What Happened

CVE-2026-93952 is an improper input-validation flaw (CWE-20) in on-premises deployments of VeloCloud Orchestrator (VCO), the self-hosted controller that configures and monitors an entire VeloCloud SD-WAN fabric. It only applies where certificate-based Edge-to-VCO authentication is enabled: an attacker who can reach the VCO web interface and has obtained the public portion of a VeloCloud Edge device’s authentication certificate can trigger the flaw and access privileged internal functionality without any operator or tenant credentials. Arista says the issue was discovered externally, not by its own testing, and is confirmed under active exploitation.

Affected releases: 5.2.x up to 5.2.3.15, 6.1.x up to 6.1.3.7, 6.4.x up to 6.4.2.7, and 7.0.x up to 7.0.0.2. Fixed releases are available now for the 5.2 branch (5.2.3.16 and later) and the 6.4 branch (6.4.2.8 and later); fixes for the 6.1 and 7.0 branches were still pending as of September 22, and Arista is directing affected customers to its TAC to confirm the correct update path. CISA added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog the same day, with a federal remediation deadline of September 25, and flagged it under BOD 26-04 as requiring forensic triage, not patching alone. Arista has published its own indicators of compromise, including hidden files and a fake system service consistent with attackers establishing persistence after initial access.

Why It Matters

An SD-WAN orchestrator isn’t one more box to patch and forget. It’s the single management plane for every branch office, routing policy and security posture the fabric enforces. This is the second time in 2026 this exact product has produced a maximum-severity, actively exploited CVE, following the unauthenticated command-injection flaw, CVE-2026-16812, DIESEC covered on July 30. Two CVSS-10.0 disclosures in the same on-premises orchestrator inside three months isn’t a one-off patch cycle anymore. It’s a pattern, and DACH organizations running VeloCloud on-premises, plus the MSPs managing those deployments, should track it as its own vendor-risk item instead of logging two separate tickets.

What You Should Do Now

  1. Patch to VCO 5.2.3.16 or later, or 6.4.2.8 or later, depending on your branch; if you run the 6.1.x or 7.0.x branch, contact Arista TAC now to confirm your update path since a general release was not yet available as of September 22.
  2. Check whether certificate-based Edge-to-VCO authentication is enabled in your deployment; this is the specific configuration the flaw requires to be reachable without credentials.
  3. Review VCO web access logs, backend application logs and system logs for suspicious activity, and check for hidden files or an unfamiliar system service, the indicators Arista itself has published.
  4. Restrict the VCO web interface to trusted management networks until you have confirmed your patch level, and review recent administrator activity for changes you cannot account for.

DIESEC Perspective

This is the same story DIESEC has now told with a dozen different vendor names in the headline this year: the device that centralizes control over a distributed network becomes the first place attackers look. A second CVSS-10.0 disclosure in the same orchestrator inside three months suggests SD-WAN controllers deserve the same ongoing exposure discipline as a firewall, not a one-time deployment and patch-when-convenient cadence.

Not sure whether your VeloCloud Orchestrator is reachable from the internet, running a patched build, or already showing signs of the published indicators of compromise? Contact DIESEC for a rapid exposure assessment and compromise check across your SD-WAN edge infrastructure.

Sources: Arista Security Advisory 0183 | SecurityWeek
Published: 2026-09-28 | Category: Vulnerabilities & Patches | ~4 min read