critical Cve 2026 93952 · Exploits

Arista VeloCloud Orchestrator Exploited at CVSS 10.0, With No Fix Listed for Two Release Trains

Data graphic: a CVSS 3.1 score of 10.0 Critical, Arista PSIRT for CVE-2026-93952 in Arista VeloCloud Orchestrator, exploited and on the CISA KEV list since 22 Sep. A 'No fix listed' stamp marks the 6.1.x and 7.0.x release trains, while only 5.2.x and 6.4.x are listed as fixed.
AK

Threat intelligence editor · Updated Oct 2, 2026, 3:28 PM EDT

Arista confirms active exploitation of CVE-2026-93952 in on-prem VeloCloud Orchestrator. CISA added it to KEV, but 6.1.x and 7.0.x have no listed fix.

Arista has confirmed active exploitation of a maximum-severity flaw in on-premises VeloCloud Orchestrator (VCO), the management plane for VeloCloud SD-WAN deployments. The bug, tracked as CVE-2026-93952, is covered by Arista Security Advisory 0183. CISA added it to its Known Exploited Vulnerabilities (KEV) catalog on 22 September 2026 with a due date of 25 September. Arista's advisory lists fixes only for the 5.2.x and 6.4.x trains. It lists none for 6.1.x or 7.0.x.

Who is affected

Only self-managed, on-prem VCO is in scope for remediation. Arista says hosted VCO, including Dedicated, was also impacted but has already been patched.

Affected on-prem versions, per the advisory and the NVD record:

  • 5.2.0 through 5.2.3.15
  • 6.1.0 through 6.1.3.7
  • 6.4.0 through 6.4.2.7
  • 7.0.0 through 7.0.0.2

Fixed releases named by Arista are 5.2.3.16 and later, and 6.4.2.8 and later. The advisory adds that "Releases in other release trains that fix this will be added over time." As of Arista Security Advisory 0183 revision 1.1 (dated 23 September 2026, re-checked on 3 October 2026), no fixed release is named for 6.1.x or 7.0.x. Operators on those trains have mitigations only, so check the advisory directly for later revisions.

What we know about the flaw

Arista's description is brief: VCO on-prem "has a security issue" that may let a remote attacker access privileged internal functionality and impact the VCO host. NVD adds that successful exploitation may compromise the confidentiality, integrity and availability of the orchestrator and the data it manages. CISA's catalog names it an improper input validation vulnerability, and the record carries CWE-20. Arista says the issue was discovered externally and is known to be actively exploited.

Arista has not published the vulnerable component, the request path, the exploitation method, indicators of compromise, or who is exploiting it. CISA lists known ransomware campaign use as "Unknown." Anything beyond the sources above is speculation, and this article does not offer any.

Severity, and a caveat on the scores

Arista PSIRT assigned a CVSS 3.1 base score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) and a CVSS 4.0 base score of 9.5 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H). Both are network-reachable, need no privileges and no user interaction, and rate confidentiality, integrity and availability impact as high. NVD lists these as secondary scores from Arista; the NVD record we retrieved shows no NVD-assigned score.

The two vectors differ on attack complexity: low in 3.1, high in 4.0. Arista does not explain the difference, so treat the 10.0 as the vendor's rating rather than a measured exploitation difficulty. In practice, the KEV listing matters more than the score: exploitation is already happening.

CISA's requirements

CISA's KEV entry requires federal civilian agencies to apply vendor mitigations in line with Binding Operational Directive 26-04 and CISA's Forensics Triage Requirements, with a due date of 25 September. The entry is flagged for forensic triage. For cloud services it points to BOD 26-04, and it says to discontinue use of the product if mitigations are unavailable. Because 6.1.x and 7.0.x have no named fix, that last clause is directly relevant to anyone running them. Private-sector teams should read the same entry as a signal to look for compromise, not only to patch.

What defenders should do

  1. Inventory. Find every on-prem VCO and its version. Anything inside the four affected ranges is exposed.
  2. Patch where a fix exists. Move 5.2.x to 5.2.3.16 or later and 6.4.x to 6.4.2.8 or later.
  3. Restrict access now. Arista's first listed mitigation is to limit the VCO web interface to trusted administrative networks. Do this on every version, including patched ones, and especially on 6.1.x and 7.0.x.
  4. Watch for malicious source IPs and unexpected outbound traffic. Block outbound ports the orchestrator does not need.
  5. Hunt for persistence. Arista specifically advises monitoring for backdoor daemons and webshells and reviewing recent administrator activity for unexpected changes. Given the exploitation status and the KEV forensic-triage flag, treat any exposed, unpatched VCO as potentially compromised and investigate before trusting it.
  6. Plan for the unfixed trains. For 6.1.x and 7.0.x, track the advisory for added releases and ask Arista support about timing and upgrade paths. Do not assume a fix.

A compromised orchestrator is high-value because it manages the SD-WAN estate, so scope the investigation to what the VCO host can reach, not just the host itself.

Related coverage

We covered a separate VeloCloud Orchestrator flaw in July: CVE-2026-16812. Arista's advisory for this bug does not mention it.

Sources

Keep reading

All latest →
  1. highExploitsZyxel GS1900 switch overflow exploited on 996 devices, now in CISA KEV4 min
  2. highExploitsMicrosoft SharePoint CVE-2026-65660 Added to CISA KEV After Rescore to RCE5 min
  3. criticalExploitsWSO2 API Manager JWT Bypass Exploited 133 Days After the Fix5 min
  4. criticalExploitsF5 BIG-IP APM: An Oversized Bearer Token Is Enough for Unauthenticated RCE6 min
  5. highExploitsApple Patches CoreGraphics Zero-Day Used Against Targeted iPhone Users5 min
  6. highExploitsWordPress Core Flaw CVE-2026-87902 Drew Exploit Attempts on Patch Day7 min