CISA Adds Critical VeloCloud Orchestrator Vulnerability to Actively Exploited Catalog
CISA added CVE-2026-93952 in VeloCloud Orchestrator On-Prem to the KEV catalog. Arista confirmed active exploitation of the vulnerability, which has a CVSS score of 10.0.

VeloCloud CVE-2026-93952 was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 22, 2026. Arista also classified the vulnerability in VeloCloud Orchestrator (VCO) On-Prem as actively exploited. According to the vendor, the flaw has the maximum CVSS v3.1 score of 10.0 and could lead to the compromise of the orchestrator host system and the data it manages.
The vulnerability is tracked as CVE-2026-93952 and involves improper input validation, classified as CWE-20. It could expose privileged internal VCO functionality to a remote attacker. This is therefore not merely a theoretical flaw: its inclusion in KEV and the vendor’s statement confirm known active exploitation.
VeloCloud CVE-2026-93952: Which Versions Are Vulnerable
Arista lists the vulnerability in selected versions of the VCO On-Prem 5.2.x, 6.1.x, 6.4.x, and 7.0.x product branches. Available fixes currently cover VCO 5.2.3.16 and later and 6.4.2.8 and later. The vendor has announced that fixes for additional supported branches will be added.
At the time the advisory was issued, no fixed releases had been listed for the 6.1.x and 7.0.x branches. Hosted deployments, including Dedicated versions, had already been fixed according to Arista. The primary concern is therefore organizations running VCO in their own infrastructure.
Exploitation Does Not Require Credentials
According to Arista, exposure requires network access to the VCO web interface, certificate-based Edge–VCO authentication configuration, and access to the public portion of the Edge certificate. The attacker does not need tenant or operator credentials.
The risk is particularly critical for VCO On-Prem systems accessible from the internet or a broadly accessible network. A compromised orchestrator handles centrally managed SD-WAN data, so an incident could affect its confidentiality, integrity, and availability. Arista also states that VeloCloud Edge devices could be affected.
What Administrators Should Do
Operators should first verify the VCO On-Prem branch and specific version in use. For the 5.2.x and 6.4.x branches, available fixed releases should be deployed promptly. For 6.1.x and 7.0.x deployments, administrators should monitor the vendor for the release of fixes.
Arista recommends restricting access to the VCO web interface to trusted administrative networks. When checking for possible compromise, administrators should especially monitor for unexpected outbound communication from the VCO host, webshells or backdoor processes, and unusual administrative changes.
There is currently no public information about the attacker, affected organizations, the campaign’s scope, or the technical details of the exploitation. It has also not been confirmed that CVE-2026-93952 is being used in ransomware campaigns. Further important information will include fixes for the remaining supported branches and any publication of indicators of compromise or exploit code.
Sources
- Arista Security Advisory 0183 – Confirms the vulnerable versions, CVSS score, exposure conditions, active exploitation, available fixes, and post-compromise recommendations.
- CISA Known Exploited Vulnerabilities Catalog – Confirms that CVE-2026-93952 was added to the KEV catalog on September 22, 2026, and that U.S. federal civilian agencies must address the vulnerability under the applicable guidelines.
Verified and updated: September 23, 2026 06:23



