New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Overview
A newly discovered vulnerability in the VeloCloud Orchestrator (VCO), identified as CVE-2026-93952, is being actively exploited by attackers. This flaw affects on-premises VCO systems, particularly those configured to authenticate Edge devices using certificates. The vulnerability allows remote attackers to access internal functions without needing login credentials, which could compromise the VCO host. This is a significant concern for organizations using VeloCloud's SD-WAN solutions, as it could lead to unauthorized access and potential data breaches. Users of VeloCloud should take immediate action to protect their systems from this exploitation.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: VeloCloud Orchestrator (VCO), Arista's SD-WAN solutions; specifically, VCO systems configured for certificate-based authentication.
- Action Required: Organizations should review their VeloCloud Orchestrator configurations and consider disabling certificate-based authentication if possible.
- Timeline: Newly disclosed
Original Article Summary
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are
Impact
VeloCloud Orchestrator (VCO), Arista's SD-WAN solutions; specifically, VCO systems configured for certificate-based authentication.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Organizations should review their VeloCloud Orchestrator configurations and consider disabling certificate-based authentication if possible. They should also monitor for any unusual activity and apply any patches or updates provided by Arista as soon as they are available.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, Arista.