Arista VeloCloud Orchestrator vulnerability

An Arista VeloCloud Orchestrator vulnerability (CVSS 10.0) lets attackers reach privileged functions with no credentials. Patch and hunt for backdoors now.

An Arista VeloCloud Orchestrator vulnerability, CVE-2026-93952 (CVSS 10.0), lets an attacker reach privileged internal functions on the on-premises controller for an entire SD-WAN fabric without any credentials at all. Arista confirmed active exploitation and shipped a patch on September 22. This is the second maximum-severity CVE in this exact product line in 2026, after the…

Read More

Arista VeloCloud Orchestrator CVE-2026-16812 Exploited

Arista VeloCloud Orchestrator CVE-2026-16812 (CVSS 10.0) is under active attack. Unauthenticated command injection lets attackers seize full SD-WAN control.

Arista VeloCloud Orchestrator CVE-2026-16812 is a maximum-severity, unauthenticated command injection flaw under active exploitation right now, and it hands an attacker control of an entire SD-WAN fabric from a single unpatched management console. CISA added it to the Known Exploited Vulnerabilities catalog on July 27, with a federal patch deadline of July 30. If your…

Read More