Actively Exploited CVSS 10 Flaw Affects VeloCloud Orchestrator

Arista has warned that attackers are actively exploiting CVE-2026-93952, a maximum-severity vulnerability in on-premises VeloCloud Orchestrator (VCO). The company assigned the flaw a CVSS 3.1 score of 10.0 and said it can allow a remote attacker without login access to privilege internal functions and affect the VCO host.
VCO manages Edge devices in a VeloCloud SD-WAN deployment. A successful attack could compromise the orchestrator and the data it manages, and could also provide access to managed Edge devices. Arista said the issue was discovered externally and is known to be actively exploited, without disclosing when exploitation began or how broadly it has occurred.
Certificate-based deployments are in scope
The exposure applies when certificate-based authentication from VeloCloud Edge to VCO is configured. VeloCloud supports three Edge authentication modes: Certificate Deactivated, which uses a pre-shared key, plus Certificate Acquire and Certificate Required, which use a certificate issued by the orchestrator.
Arista did not specify which certificate modes meet the affected condition. It said an attacker also needs network access to the VCO web interface and the public portion of an Edge authentication certificate. This distinguishes the new issue from CVE-2026-16812, the VCO flaw Arista reported as exploited in July: that earlier issue affected VCO by default and could not be avoided through configuration.
Patch status varies by release train
As of September 22, fixes are available in VCO 5.2.3.16 and later for affected 5.2.3.15 and earlier releases. For the 6.4 train, the fix is in 6.4.2.8 and later, covering affected 6.4.2.7 and earlier versions.
Arista had not yet released fixes for affected versions in the 6.1 and 7.0 trains. The affected ranges are 6.1.3.7 and earlier, and 7.0.0.2 and earlier. The company said fixes for supported affected trains will be added to its advisory when ready. Customers using an unsupported train should contact Arista Technical Assistance Center for upgrade options. Hosted and Dedicated VCO versions have already been patched.
Contain exposure and preserve evidence
Until a fixed release can be installed, Arista recommends limiting VCO web-interface access to trusted administrative networks, monitoring for known malicious IP addresses and unexpected outbound traffic, and considering blocks on outbound ports not required for normal operations. Teams should also monitor for backdoor daemons, webshells, and unexpected administrator changes.
Arista noted that no single indicator confirms compromise through this flaw. Investigators should examine VCO web-access logs for unusual URL-like paths, encoded characters, local or internal service references, and high request rates. Listed indicators include /usr/local/sbin/.vcnode.js, /usr/local/sbin/vc-sysmond, the nginx header x-vc-opt, and the IP addresses 142.93.149[.]77 and 104.248.126[.]159.
If indicators are found, Arista advises preserving the VCO state and retaining web-access, backend application, system, and database logs, plus file-system timestamps where practical, before making changes. After upgrading, incident response may require credential rotation, administrator-activity review, validation of managed Edge devices, and restoration or replacement of the orchestrator from trusted sources. For businesses, the immediate priority is to identify certificate-based VCO deployments, apply available fixes, and restrict management-plane access while unpatched systems remain in service.

