Posts Tagged ‘CVE-2026-93952’
Arista VeloCloud Orchestrator vulnerability
An Arista VeloCloud Orchestrator vulnerability, CVE-2026-93952 (CVSS 10.0), lets an attacker reach privileged internal functions on the on-premises controller for an entire SD-WAN fabric without any credentials at all. Arista confirmed active exploitation and shipped a patch on September 22. This is the second maximum-severity CVE in this exact product line in 2026, after the…
Read More
