Arista Networks disclosed the actively exploited zero-day on Tuesday, warning that "access to the public portion of the VeloCloud Edge authentication certificate is required" for a successful attack. The company stated that the issue was discovered externally and is known to be actively exploited. The vulnerability (CVE-2026-93952) carries a maximum CVSS severity rating and affects VCO instances where certificate-based authentication from VeloCloud Edge to the Orchestrator is configured. Attackers need network access to the VCO web interface but do not require tenant or operator credentials.
VeloCloud Orchestrator is a cloud-based centralized management platform used by administrators to configure, monitor, and manage VeloCloud SD-WANs and associated edge devices. Arista has already patched hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later, and plans to release patches for older versions including 6.1.3.7 and below, and 7.0.0.2 and below.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on Tuesday and issued a binding operational directive requiring U.S. federal civilian executive branch agencies to apply mitigations by September 25. Arista provided indicators of compromise, advising administrators to restrict access to the VCO web interface to administrative networks, review recent administrator activity, and monitor for connections from known malicious IP addresses. The company specifically listed IP addresses 142.93.149.77 and 104.248.126.159 as associated with exploitation, and urged teams to review nginx logs for the x-vc-opt HTTP header. Unexpected outbound HTTP or HTTPS traffic from the VCO host may also signal compromise.
"If compromise is suspected, operators should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible," Arista advised, directing customers to contact its Technical Assistance Center for further support.
The company has patched two other zero-day vulnerabilities earlier this year — CVE-2026-7473 in May and an additional flaw.