Arista Networks has released patches for CVE-2026-93952, a maximum-severity input-validation flaw in VeloCloud Orchestrator (VCO) On-Prem deployments that the company says is being actively exploited.
The vulnerability affects deployments configured to use certificate-based authentication from VeloCloud Edge to VCO. Remote attackers can exploit it in low-complexity attacks to access privileged internal VCO host functionality. The attacks require access to the public portion of the VeloCloud Edge authentication certificate and network access to the VCO web interface, but do not require privileges, user interaction, or VCO tenant or operator credentials.
Arista says hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later have already been patched. It plans to release patches for VCO instances running 6.1.3.7 and below and 7.0.0.2 and below.
The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog on Tuesday and ordered U.S. federal civilian executive branch agencies to secure their networks by Friday, September 25. Arista also identified 142[.]93.149.77 and 104[.]248.126.159 as IP addresses for security teams to block and recommended reviewing VCO and nginx logs for suspicious activity.
Since the start of the year, Arista has patched two other actively exploited zero-days: CVE-2026-7473 in May and CVE-2026-16812 in July. The flaws affected Extensible Operating System (EOS) and on-premises VeloCloud Orchestrator deployments, respectively. Arista says it has more than 10,000 customers worldwide.
Comments
0No comments yet. Be the first to comment.