Arista confirms active exploitation of CVE-2026-93952 in on-prem VeloCloud Orchestrator. CISA added it to KEV, but 6.1.x and 7.0.x have no listed fix.
Arista has confirmed active exploitation of a maximum-severity flaw in on-premises VeloCloud Orchestrator (VCO), the management plane for VeloCloud SD-WAN deployments. The bug, tracked as CVE-2026-93952, is covered by Arista Security Advisory 0183. CISA added it to its Known Exploited Vulnerabilities (KEV) catalog on 22 September 2026 with a due date of 25 September. Arista's advisory lists fixes only for the 5.2.x and 6.4.x trains. It lists none for 6.1.x or 7.0.x.
Who is affected
Only self-managed, on-prem VCO is in scope for remediation. Arista says hosted VCO, including Dedicated, was also impacted but has already been patched.
Affected on-prem versions, per the advisory and the NVD record:
- 5.2.0 through 5.2.3.15
- 6.1.0 through 6.1.3.7
- 6.4.0 through 6.4.2.7
- 7.0.0 through 7.0.0.2
Fixed releases named by Arista are 5.2.3.16 and later, and 6.4.2.8 and later. The advisory adds that "Releases in other release trains that fix this will be added over time." As of Arista Security Advisory 0183 revision 1.1 (dated 23 September 2026, re-checked on 3 October 2026), no fixed release is named for 6.1.x or 7.0.x. Operators on those trains have mitigations only, so check the advisory directly for later revisions.
What we know about the flaw
Arista's description is brief: VCO on-prem "has a security issue" that may let a remote attacker access privileged internal functionality and impact the VCO host. NVD adds that successful exploitation may compromise the confidentiality, integrity and availability of the orchestrator and the data it manages. CISA's catalog names it an improper input validation vulnerability, and the record carries CWE-20. Arista says the issue was discovered externally and is known to be actively exploited.
Arista has not published the vulnerable component, the request path, the exploitation method, indicators of compromise, or who is exploiting it. CISA lists known ransomware campaign use as "Unknown." Anything beyond the sources above is speculation, and this article does not offer any.
Severity, and a caveat on the scores
Arista PSIRT assigned a CVSS 3.1 base score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) and a CVSS 4.0 base score of 9.5 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H). Both are network-reachable, need no privileges and no user interaction, and rate confidentiality, integrity and availability impact as high. NVD lists these as secondary scores from Arista; the NVD record we retrieved shows no NVD-assigned score.
The two vectors differ on attack complexity: low in 3.1, high in 4.0. Arista does not explain the difference, so treat the 10.0 as the vendor's rating rather than a measured exploitation difficulty. In practice, the KEV listing matters more than the score: exploitation is already happening.
CISA's requirements
CISA's KEV entry requires federal civilian agencies to apply vendor mitigations in line with Binding Operational Directive 26-04 and CISA's Forensics Triage Requirements, with a due date of 25 September. The entry is flagged for forensic triage. For cloud services it points to BOD 26-04, and it says to discontinue use of the product if mitigations are unavailable. Because 6.1.x and 7.0.x have no named fix, that last clause is directly relevant to anyone running them. Private-sector teams should read the same entry as a signal to look for compromise, not only to patch.
What defenders should do
- Inventory. Find every on-prem VCO and its version. Anything inside the four affected ranges is exposed.
- Patch where a fix exists. Move 5.2.x to 5.2.3.16 or later and 6.4.x to 6.4.2.8 or later.
- Restrict access now. Arista's first listed mitigation is to limit the VCO web interface to trusted administrative networks. Do this on every version, including patched ones, and especially on 6.1.x and 7.0.x.
- Watch for malicious source IPs and unexpected outbound traffic. Block outbound ports the orchestrator does not need.
- Hunt for persistence. Arista specifically advises monitoring for backdoor daemons and webshells and reviewing recent administrator activity for unexpected changes. Given the exploitation status and the KEV forensic-triage flag, treat any exposed, unpatched VCO as potentially compromised and investigate before trusting it.
- Plan for the unfixed trains. For 6.1.x and 7.0.x, track the advisory for added releases and ask Arista support about timing and upgrade paths. Do not assume a fix.
A compromised orchestrator is high-value because it manages the SD-WAN estate, so scope the investigation to what the VCO host can reach, not just the host itself.
Related coverage
We covered a separate VeloCloud Orchestrator flaw in July: CVE-2026-16812. Arista's advisory for this bug does not mention it.