A critical vulnerability in the on-premises VeloCloud Orchestrator (VCO), with the identifier CVE-2026-93952 and a CVSS score of 10.0, is already being exploited in attacks. The issue affects installations that use certificates to connect Edge devices to the central orchestrator. VeloCloud Edge devices should be checked immediately.

The Hacker News reports that Arista disclosed the active exploit on September 22. A remote attacker could, without logging into an account, gain access to privileged internal functions and affect VeloCloud Orchestrator itself.
See also: Arista: Critical zero-day in VeloCloud Orchestrator
VeloCloud Edge Devices: What we know about CVE-2026-93952
VeloCloud Orchestrator is the platform that manages the Edge components of a VeloCloud SD-WAN. The new vulnerability is found in deployments where Edge devices authenticate their connection with certificates. An attacker would need access to the VCO web interface, as well as the public portion of a certificate used to identify an Edge device.
The attack can compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. The most serious possibility is the extension of the breach to the Edge devices, because the central node has management rights over the entire network.

According to the CVE Brief, CVE-2026-93952 is listed as critical, with a non-privileged network exploit and no user interaction. This rating does not mean that every installation is equally vulnerable; administrators should first review how Edge devices are authenticated.
See also: CISA: New Cisco, Citrix and Fortinet vulnerabilities in the KEV list
Affected versions and available fixes
Arista's security advisory page states that versions 5.2.3.15 and earlier are affected , while the fix for branch 5.2 is included in 5.2.3.16 and later . In branch 6.4, versions 6.4.2.7 and earlier are affected, with a fix in 6.4.2.8 . There was no fix available for branches 6.1 and 7.0 at the time of the advisory.
Hosted and Dedicated versions of VeloCloud Orchestrator have already been patched by Arista. Those using an unsupported software branch should contact the company's Technical Assistance Center for upgrade options. Moving to a patched version is the primary measure, as no secure workaround to eliminate the vulnerability.
Differentiating between branches is of practical importance to infrastructure teams assessing CVE-2026-93952. A general check that VCO is working properly is not enough: the branch, exact version, and authentication settings of each installation must be recorded. At the same time, network administrators must confirm that management is not accessible from untrusted networks and that edge device connections are monitored.

Interim measures and violation control
Until the upgrade is complete, Arista recommends restricting access to the VCO web interface to trusted management networks. Security teams should monitor connections from known malicious addresses, unexpected outbound traffic, and changes that do not correspond to administrator actions. For CVE-2026-93952, this monitoring is critical even when no symptoms have occurred.
Log checks should look for unusual request paths, encoded characters, references to local or internal services, and sudden increases in request rates. For example, the update mentions the files /usr/local/sbin/.vcnode.js , /usr/local/sbin/vc-sysmond , and /etc/systemd/system/vc-sysmon.service , as well as the HTTP header x-vc-opt . These are clues to investigate, not evidence of a breach in themselves.
In case of suspicious activity, administrators should maintain the VCO state and save web access, application, system, and database logs prior to remediation changes, where feasible. After upgrading for CVE-2026-93952, credentials should be changed, administrator actions reviewed, and the status of Edge devices confirmed.
See also: CVE-2026-21962: Critical Oracle WebLogic vulnerability being exploited
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The SecNews editorial team recommends that organizations address CVE-2026-93952 as a matter of urgency: confirm the version, check certificate configuration, immediately restrict access to the interface, and schedule a secure upgrade. Active exploitation means that the absence of obvious symptoms is not an indication of security.
