Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Arista Urges Immediate Patching of Exploited VCO Zero-Day

Remote attackers could trigger the critical-severity flaw to access privileged internal functionality.

Arista

Networking solutions provider Arista has released urgent patches for a critical-severity vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments that has been exploited as a zero-day.

VCO is a centralized management tool for configuring, monitoring, and orchestrating edge devices, policies, and traffic in Arista VeloCloud SD-WAN.

The exploited zero-day, tracked as CVE-2026-93952 (CVSS score of 10), is described as an improper input validation issue that could allow remote attackers to access privileged internal functionality.

Successful exploitation of the security defect could impact the confidentiality, integrity, and availability of the orchestrator and the data it manages.

“This issue was discovered externally and is known to be actively exploited,” Arista warns.

According to the company, the bug affects only VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom) and was resolved in VCO versions 5.2.3.16 and 6.4.2.8 in the 5.2.x and 6.1.x trains, respectively. Patches for other trains will also be released.

Advertisement. Scroll to continue reading.

“VCO is exposed if certificate-based authentication from the VeloCloud Edge to VCO is configured. Access to the public portion of the VeloCloud Edge authentication certificate is required. A successful attack requires network access to the VCO web interface. VCO tenant or operator credentials are not required for this exposure,” the company notes.

Arista says that deployments that limit access to the VCO web interface have a lower risk of exposure, but urges updating to a fixed release.

The company noted that there are no definitive indicators of compromise (IoCs), recommending administrators review VCO web access logs, backend application logs, and system logs for suspicious activity.

CVE-2026-93952 was added to CISA’s Known Exploited Vulnerabilities (KEV) list on Tuesday. In line with BOD 26-04’s recommendations, federal agencies were given three days to patch it.

Related: Critical F5 BIG-IP APM Vulnerability Exploited as a Zero-Day

Related: Check Point Patches Exploited Management Server Zero-Day

Related: Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity

Related: Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Veritas Capital has appointed Joel Fulton as Chief Information Security Officer.

incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.

Ruben D. Chacon has joined ADM as Vice President and Global CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.