Arista VeloCloud Orchestrator Zero-Day CVE-2026-93952 Hits CVSS 10.0, Lands on CISA KEV With Active Exploitation
Arista VeloCloud Orchestrator Zero-Day CVE-2026-93952 Hits CVSS 10.0, Lands on CISA KEV With Active Exploitation
Arista Networks has released security patches for a maximum-severity zero-day in the on-premises VeloCloud Orchestrator (VCO) — the centralized platform that manages VeloCloud SD-WANs and their edge devices — and says the flaw is already being exploited in attacks. The vulnerability, tracked as CVE-2026-93952, received a CVSS 3.1 score of 10.0, and CISA added it to its Known Exploited Vulnerabilities catalog on September 22, giving federal agencies until Friday, September 25 to secure their networks. It is the second edge-device flaw to hit the catalog this week, after the Zyxel switch compromise disclosed a day earlier.
The flaw stems from improper input validation and affects only on-premises VCO deployments where certificate-based authentication from the VeloCloud Edge to the Orchestrator is configured. Exploitation is remote, requires no privileges on the target, no VCO tenant or operator credentials, and no user interaction — but the attacker does need network access to the VCO web interface and the public portion of an Edge's authentication certificate. A successful attack can reach privileged internal functions on the VCO host, and because the orchestrator manages every Edge in the SD-WAN, a compromised VCO can also open the door to the devices it manages.
"This issue was discovered externally and is known to be actively exploited," Arista said in its September 22 advisory. The company did not say when the attacks began or how widespread they are.
Patch Status and Gaps
Hosted and Dedicated VCO deployments are already patched. For on-premises orchestrators, the fixed releases cover two of four release trains: VCO 5.2.3.16 and later, and 6.4.2.8 and later. For the 6.1 train (6.1.3.7 and earlier) and the 7.0 train (7.0.0.2 and earlier), fixes are not out yet — Arista says patches for supported trains are coming and will be added to its advisory. It is Arista's third exploited zero-day this year, after CVE-2026-7473 in May (EOS) and CVE-2026-16812 in July, which also hit on-premises VCO deployments but was exploitable in the default configuration, with no settings that could prevent it.
What Should You Do?
- Check your Edge authentication mode. Only orchestrators using certificate-based Edge authentication (Certificate Acquire or Required modes) are exposed; PSK-based setups are not.
- Upgrade to 5.2.3.16+ or 6.4.2.8+ if you run an on-premises VCO on a fixed train. If you are on 6.1 or 7.0, plan the upgrade path now and contact Arista TAC about interim options.
- While unpatched, restrict the VCO web interface to trusted administrative networks — the single most effective exposure cut, since exploitation requires web access.
- Hunt for the published indicators. Arista's IoCs: the files /usr/local/sbin/.vcnode.js and /usr/local/sbin/vc-sysmond (MD5 dc78e206eaeadec59fc5801fe4556bd0), a vc-sysmon.service systemd unit, an x-vc-opt HTTP header in nginx logs, and connections to 142[.]93.149.77 and 104[.]248.126.159. Preserve VCO logs and file-system timestamps before remediating.
- Watch outbound traffic from the VCO host and review recent administrator activity for unexpected changes; block outbound ports that normal operation doesn't need.
The WAF Angle
An orchestrator is a control plane: whoever owns it owns every device beneath it. That makes VCO a juicier target than any single Edge, and it explains why the exploit skips credentials entirely and goes for the web interface's input handling. Two lessons travel well beyond SD-WAN. First, management planes that listen on the network need the same request-inspection discipline as production apps — unusual URL-like paths, encoded characters, and references to internal services in requests to your management tooling are exactly what a WAF in front of an admin interface should be flagging, and exactly what Arista's own log-review guidance describes. Second, note the pattern in the July flaw versus this one: attackers returned to the same product within two months, exploiting a different condition. Assume persistence and re-check compromise indicators even after this patch, and treat "we already patched the previous zero-day" as no kind of assurance.