Actively Exploited VeloCloud Orchestrator Flaw Scores 10.0
VeloCloud Orchestrator coordinates the Edge devices in a software-defined wide area network. Arista says the vulnerability was discovered externally but has not identified the attackers, the number of affected organizations or when exploitation began. The Hacker News reported that this is a separate VeloCloud issue from one Arista disclosed in July; installing that earlier fix does not necessarily address the new flaw.
Arista classifies CVE-2026-93952 as improper input validation. Exposure requires an on-premises orchestrator configured for certificate-based Edge authentication, access to the public portion of an Edge authentication certificate, and network access to the VCO web interface. Tenant or operator login credentials are not required. The vendor has not published a full exploit chain, so these conditions should not be read as evidence that every VCO installation is reachable.
Affected releases include 5.2.3.15 and earlier in the 5.2 train, 6.1.3.7 and earlier in 6.1, 6.4.2.7 and earlier in 6.4, and 7.0.0.2 and earlier in 7.0. Arista says no single indicator proves compromise. Its advisory asks operators to investigate unusual web requests and lists the x-vc-opt HTTP header, files at /usr/local/sbin/vc-sysmond and /etc/systemd/system/vc-sysmon.service, and connections from 142.93.149.77 or 104.248.126.159 as indicators warranting review.
Arista has released fixed VCO versions 5.2.3.16 and 6.4.2.8; fixes for other supported trains are pending. It says hosted and dedicated VCO instances have already been patched. Until an on-premises update is available, the vendor advises restricting the VCO web interface to trusted administrative networks, monitoring unexpected outbound traffic and reviewing recent administrator activity.
Organizations running exposed VCO servers should check their version and Edge authentication settings, apply the matching fixed release when available, and preserve relevant logs if compromise is suspected. Arista advises affected operators to assess managed Edge devices and consider credential rotation or restoration from trusted sources during incident response. The advisory remains the source for additional fixes and indicators as they are released.