Arista Patches Actively Exploited Zero-Day in VeloCloud Orchestrator

Maximum-severity flaw CVE-2026-93952 allows remote access to internal VCO functions; CISA orders federal agencies to patch by Friday

By LineZotpaper
Published
Read Time2 min
Arista Networks has released security patches for a maximum-severity zero-day vulnerability affecting VeloCloud Orchestrator (VCO) On-Prem deployments that is being actively exploited in the wild. The flaw, tracked as CVE-2026-93952, stems from improper input validation in deployments using certificate-based authentication and allows remote attackers to access privileged internal VCO host functionality without requiring user interaction or prior privileges. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal civilian agencies to secure their networks by Friday, September 25.

Arista Networks disclosed the actively exploited zero-day on Tuesday, warning that "access to the public portion of the VeloCloud Edge authentication certificate is required" for a successful attack. The company stated that the issue was discovered externally and is known to be actively exploited. The vulnerability (CVE-2026-93952) carries a maximum CVSS severity rating and affects VCO instances where certificate-based authentication from VeloCloud Edge to the Orchestrator is configured. Attackers need network access to the VCO web interface but do not require tenant or operator credentials.

VeloCloud Orchestrator is a cloud-based centralized management platform used by administrators to configure, monitor, and manage VeloCloud SD-WANs and associated edge devices. Arista has already patched hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later, and plans to release patches for older versions including 6.1.3.7 and below, and 7.0.0.2 and below.

CISA added the flaw to its Known Exploited Vulnerabilities catalog on Tuesday and issued a binding operational directive requiring U.S. federal civilian executive branch agencies to apply mitigations by September 25. Arista provided indicators of compromise, advising administrators to restrict access to the VCO web interface to administrative networks, review recent administrator activity, and monitor for connections from known malicious IP addresses. The company specifically listed IP addresses 142.93.149.77 and 104.248.126.159 as associated with exploitation, and urged teams to review nginx logs for the x-vc-opt HTTP header. Unexpected outbound HTTP or HTTPS traffic from the VCO host may also signal compromise.

"If compromise is suspected, operators should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible," Arista advised, directing customers to contact its Technical Assistance Center for further support.

The company has patched two other zero-day vulnerabilities earlier this year — CVE-2026-7473 in May and an additional flaw.

§

Analysis

Why This Matters

  • The vulnerability targets a central management platform for SD-WAN infrastructure, which if compromised could allow attackers to pivot into an organization's wide-area network and affect branch offices and remote sites.
  • Active exploitation in the wild means immediate risk for unpatched VCO On-Prem deployments; CISA's directive signals high confidence in adversary usage.
  • The attack does not require credentials, lowering the barrier for initial access; organizations relying on perimeter defenses alone may be exposed.

Background

VeloCloud Orchestrator is the management plane for Arista's VeloCloud SD-WAN solution, used by enterprises to centrally configure and monitor edge networking devices. On-premises deployments place this control plane inside the customer's network, making them responsible for patching. The vulnerability exploits the certificate-based authentication handshake between edge devices and the orchestrator, allowing an unauthenticated attacker with network access to the web interface to execute privileged operations.

Key Perspectives

Arista Networks: The vendor has released patches for current hosted versions and is preparing updates for older deployments. It has provided detailed indicators of compromise and remediation steps, including specific IP blocks and log review guidance. CISA: The agency has mandated federal agencies patch within three days, reflecting the severity and confirmed exploitation. This also sends a signal to critical infrastructure operators outside government. Network administrators: IT teams must prioritize patching while following Arista's recommended monitoring and access restrictions. The narrow patch window — especially for older versions without immediate fixes — may leave some systems exposed.

What to Watch

  • Whether Arista meets its self-imposed deadline for patching VCO versions 6.1.3.7 and below and 7.0.0.2 and below.
  • Reports of secondary exploitation or ransomware groups incorporating the vulnerability into their arsenals.
  • CISA's Known Exploited Vulnerabilities catalog may be updated with further indicators or mitigation bypass techniques.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.