Networking solutions provider Arista has released urgent patches for a critical-severity vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments that has been exploited as a zero-day.
VCO is a centralized management tool for configuring, monitoring, and orchestrating edge devices, policies, and traffic in Arista VeloCloud SD-WAN.
The exploited zero-day, tracked as CVE-2026-93952 (CVSS score of 10), is described as an improper input validation issue that could allow remote attackers to access privileged internal functionality.
Successful exploitation of the security defect could impact the confidentiality, integrity, and availability of the orchestrator and the data it manages.
“This issue was discovered externally and is known to be actively exploited,” Arista warns.
According to the company, the bug affects only VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom) and was resolved in VCO versions 5.2.3.16 and 6.4.2.8 in the 5.2.x and 6.1.x trains, respectively. Patches for other trains will also be released.
“VCO is exposed if certificate-based authentication from the VeloCloud Edge to VCO is configured. Access to the public portion of the VeloCloud Edge authentication certificate is required. A successful attack requires network access to the VCO web interface. VCO tenant or operator credentials are not required for this exposure,” the company notes.
Arista says that deployments that limit access to the VCO web interface have a lower risk of exposure, but urges updating to a fixed release.
The company noted that there are no definitive indicators of compromise (IoCs), recommending administrators review VCO web access logs, backend application logs, and system logs for suspicious activity.
CVE-2026-93952 was added to CISA’s Known Exploited Vulnerabilities (KEV) list on Tuesday. In line with BOD 26-04’s recommendations, federal agencies were given three days to patch it.
Related: Critical F5 BIG-IP APM Vulnerability Exploited as a Zero-Day
Related: Check Point Patches Exploited Management Server Zero-Day
Related: Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity
Related: Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard
