News

Arista Warns Admins to Patch a CVSS 10 VeloCloud Zero-Day Already Used Against Orchestrators

Arista shipped fixes for CVE-2026-93952, a CVSS 10.0 zero-day in on-premises VeloCloud Orchestrator that is already being exploited. Only certificate-based setups are exposed, and the 6.1 and 7.0 trains have no fix yet.

Arista Warns Admins to Patch a CVSS 10 VeloCloud Zero-Day Already Used Against Orchestrators

Arista is telling network administrators to patch a critical flaw in its on-premises VeloCloud Orchestrator right now, because attackers are already exploiting it.

The bug, tracked as CVE-2026-93952, carries a maximum CVSS 3.1 severity score of 10.0. VeloCloud Orchestrator, or VCO, is the server that manages the Edge devices across a VeloCloud SD-WAN, so a foothold there reaches deep into a network.

A remote attacker with no login can reach privileged internal functions and compromise the VCO host, Arista said in a September 22 advisory. The damage does not stop there: a compromised orchestrator can also reach the Edge devices it manages and the data flowing through them.

Not every deployment is exposed, and the distinction matters. Only orchestrators configured to authenticate their Edges with certificates are at risk. Setups that use a pre-shared key in Certificate Deactivated mode are not. An attacker also needs network access to the VCO web interface and the public part of an Edge's authentication certificate.

Arista said the flaw "was discovered externally and is known to be actively exploited," but stopped short of saying when the attacks began or how many customers have been hit.

The patch picture is uneven. Arista has already fixed its Hosted and Dedicated VCO versions, and on-premises fixes are out for the 5.2 train (5.2.3.16 and later) and the 6.4 train (6.4.2.8 and later). As of September 22 there was still no fix for the 6.1 and 7.0 trains, leaving those customers with mitigations only.

That gap stings because a related VCO flaw was already exploited in July. The earlier bug, CVE-2026-16812, exposed orchestrators by default with no setting able to prevent it, while this one is at least gated behind certificate-based authentication.

Until a fixed release lands, Arista recommends limiting the VCO web interface to trusted administrative networks, watching for unexpected outbound traffic, and hunting for backdoor daemons and webshells. Its indicators of compromise include the files /usr/local/sbin/.vcnode.js and /usr/local/sbin/vc-sysmond, an nginx header x-vc-opt, and the IP addresses 142.93.149.77 and 104.248.126.159.

The scramble echoes recent gateway emergencies, from the F5 BIG-IP APM OAuth zero-day exploited before its patch existed to the SonicWall SMA1000 zero-days under active attack. Each one hands attackers a widely deployed edge device and a race against defenders.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free