Arista Patches Actively Exploited VeloCloud Orchestrator Zero-Day
Arista Networks has released a security patch for an actively exploited zero-day vulnerability affecting on-premises VeloCloud Orchestrator (VCO) deployments.
VCO is a centralized management platform that helps administrators configure, monitor, and manage VeloCloud Software-Defined Wide Area Network (SD-WAN) environments and associated edge devices.
Tracked as CVE-2026-93952, the maximum-severity flaw is caused by improper input validation. It affects VCO deployments configured to use certificate-based authentication between VeloCloud Edge and VeloCloud Orchestrator.
A remote attacker could exploit the vulnerability to access privileged internal VCO host functionality. The attack has low complexity and does not require privileges on the target system or user interaction.
“This issue has been discovered externally and is known to be actively exploited,” Arista warned in a Tuesday security advisory.
“Access to the public portion of the VeloCloud Edge authentication certificate is required. A successful attack requires network access to the VCO web interface. This breach does not require VCO tenant or operator credentials.”
Arista releases VCO security updates
Arista says it has already patched hosted deployments running VCO 5.2.3.16 and later, as well as VCO 6.4.2.8 and later.
The company also plans to release security updates for VCO instances running 6.1.3.7 and earlier and 7.0.0.2 and earlier.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-93952 to its Known Exploited Vulnerabilities Catalog on Tuesday. CISA ordered U.S. federal civilian executive branch agencies to protect their networks against the flaw by Friday, September 25.
How to detect potential VCO compromise
While security patches are being deployed, administrators should restrict access to the VCO web interface to the management network, review recent administrator activity for unusual changes, and monitor connections from known malicious IP addresses.
Security teams should also review VCO web access logs for suspicious activity, including requests containing encoded characters, unusual path components, URLs referencing local or internal services, and unusually high request rates.
Arista advised security teams to block the following IP addresses:
142[.]93.149.77104[.]248.126.159
Administrators should also check nginx logs for the x-vc-opt HTTP header. Unexpected outbound HTTP or HTTPS activity originating from the VCO host may require further investigation.
“If a breach is suspected, operators should, to the extent operationally possible, preserve the VCO’s web access logs, back-end application logs, system logs, database logs, and associated file system timestamps prior to remediation,” Arista said. The company advised customers to contact the Arista Networks Technical Assistance Center (TAC) for additional assistance.
Arista has disclosed other exploited zero-days
Since the beginning of the year, Arista has reported two other zero-day vulnerabilities: CVE-2026-7473 and CVE-2026-16812.
The flaws were actively exploited in attacks in May and July, respectively, and affected Extensible Operating System (EOS) and on-premises VeloCloud Orchestrator deployments.
Arista Networks is a Fortune 500 company and one of the largest companies in the United States by revenue, with more than 10,000 customers worldwide.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



