Arista has issued an urgent security warning regarding a critical vulnerability affecting on-premises deployments of the VeloCloud Orchestrator (VCO), the central management server utilized to control Edge devices across software-defined wide area network (SD-WAN) architectures. The security flaw, which has been assigned the identifier CVE-2026-93952, is currently being actively exploited in the wild by malicious actors.

The vulnerability carries a maximum severity rating of 10.0 on the Common Vulnerability Scoring System (CVSS v3.1), reflecting the severe potential impact of a successful exploitation attempt. According to Arista’s advisory published on September 22, the security defect could allow an unauthenticated remote attacker to manipulate internal functions and compromise the underlying VCO host. Furthermore, because the orchestrator holds administrative and operational control over connected network infrastructure, a successful compromise of the VCO can potentially grant attackers unauthorized access to the downstream Edge devices it manages, posing a widespread threat to enterprise network integrity and data security.

The active exploitation of CVE-2026-93952 marks the second major security crisis to impact on-premises VeloCloud Orchestrator installations in recent months. In July, Arista disclosed a separate critical vulnerability—tracked as CVE-2026-16812—that attackers also weaponized in real-world campaigns. While the July flaw affected deployments universally by default regardless of configuration settings, the latest vulnerability specifically targets environments configured with particular security parameters.

Which Deployments Are Exposed

Understanding the attack surface requires examining how VeloCloud Edges communicate and authenticate with the central orchestrator. VeloCloud Edges can be provisioned to authenticate to the VCO using one of three distinct operational modes. In environments utilizing Certificate Deactivated mode, Edge devices rely on a pre-shared key (PSK) to establish trust. Conversely, environments operating under Certificate Acquire or Certificate Required modes utilize cryptographic certificates issued directly by the orchestrator.

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

Arista has clarified that the newly disclosed vulnerability exclusively impacts orchestrators that are configured to authenticate their Edge devices using certificates. Consequently, organizations utilizing pre-shared keys are not directly exposed to this specific vector. However, exploiting the flaw requires more than just a specific configuration setting. An attacker must possess network-level access to the VCO web interface, alongside knowledge of the public portion of an Edge device’s authentication certificate. Despite these prerequisite conditions, the fact that threat actors are actively leveraging the flaw in live attacks underscores the urgency for affected organizations to evaluate their current deployment models and implement available security updates.

Patch Availability and Affected Release Trains

In response to the active exploitation campaign, Arista’s engineering teams have moved quickly to develop and release software patches for several major software release trains, though fixes for other branches remain in development. As of September 22, patched versions have been made available for the 5.2 and 6.4 release trains, while updates for the 6.1 and 7.0 trains are still pending. Additionally, Arista confirmed that its cloud-hosted and dedicated managed versions of the VCO have already been secured against the threat.

Within the 5.2 release train, versions 5.2.3.15 and earlier are vulnerable to CVE-2026-93952. Arista has addressed this issue in version 5.2.3.16 and all subsequent releases. For context, the earlier July flaw in this train was patched in version 5.2.3.14.

The situation differs for the 6.1 release train, where versions up to and including 6.1.3.7 remain affected by the new vulnerability. As of the September 22 advisory, a formal software fix has not yet been released for this branch, although the July flaw was previously remedied in version 6.1.3.4.

Similarly, within the 6.4 train, versions 6.4.2.7 and earlier are susceptible to the exploit, prompting the release of version 6.4.2.8 and later as the definitive fix, following the earlier patch for the July vulnerability in version 6.4.2.4.

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

Finally, for organizations utilizing the 7.0 train, versions up to 7.0.0.2 are affected by CVE-2026-93952, and an official software update is still pending. Arista noted that versions 7.0.0.1 and later were not impacted by the earlier July flaw.

Arista has committed to rolling out patches for all remaining supported release trains as soon as they become finalized and thoroughly tested. Organizations operating on unsupported software release trains are urged to reach out directly to Arista’s Technical Assistance Center (TAC) to explore available migration pathways, custom upgrade options, or alternative mitigation strategies.

Identifying Signs of Compromise and Incident Response

Because automated scanning and exploitation campaigns are underway, Arista has emphasized the importance of proactive threat hunting and forensic analysis across enterprise environments. The company noted that there is no single, definitive indicator that instantly confirms whether a specific VeloCloud Orchestrator has been successfully breached via this vulnerability. Instead, system administrators and security teams must meticulously review VCO web access logs for anomalous activity, such as incoming requests characterized by unusual URL-like structures, heavily encoded character strings, direct references to local or internal system services, or abnormally high request frequencies indicative of automated probing or brute-force attempts.

If security personnel uncover any suspicious log entries or anomalies indicative of unauthorized access, Arista strongly advises preserving the current operational state of the VCO immediately before attempting any remediation or patching procedures. Organizations should systematically export and securely archive the orchestrator’s web access logs, backend application logs, system logs, database logs, and file-system timestamps. Preserving these forensic artifacts is essential for conducting an effective root-cause analysis and understanding the full scope of any potential intrusion.

Once the immediate forensic data has been preserved and the necessary software upgrades have been successfully applied, organizations should initiate a comprehensive post-incident response protocol. This secondary phase of remediation typically involves rotating administrative credentials, auditing recent user activity and configuration changes within the orchestrator, and thoroughly inspecting the operational health and integrity of all managed Edge devices deployed across the wide area network. In severe cases of confirmed compromise, security teams may need to completely rebuild, restore, or replace the orchestrator instance using clean, trusted backups and verified source images to ensure complete eradication of any persistent unauthorized access mechanisms.

Leave a Reply

Your email address will not be published. Required fields are marked *