CVE-2026-93952
CVSS 10 CRITICAL: veloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. EPSS 0.4% (36th percentile).
Vulnerabilities · 4h ago
Arista said on September 22 that CVE-2026-93952 is being actively exploited against certificate-authenticated on-premises VeloCloud Orchestrators, with fixes already available for the 5.2 and 6.4 release trains and Hosted and Dedicated VCO, but still pending for 6.1 and 7.0. The flaw carries a CVSS 10.0 score.
The weakness sits in the trust model. If an attacker can reach the VCO web interface and has the public part of an Edge certificate, they can abuse internal functions without a normal login, compromise the orchestrator, and reach the Edge devices it manages. In plain terms, the controller is the trust broker for the fleet, so one server breach can become control of the managed network.
For operators running certificate-based VCO, the exposure is not a single-host event; it is the management plane for every enrolled Edge. That makes the pending-release trains and any deployment that still treats the orchestrator like an ordinary server the places to watch most closely.
CVSS 10 CRITICAL: veloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. EPSS 0.4% (36th percentile).
2 sources covering this story
Kwetsbaarheid verholpen in VeloCloud Orchestrator (VCO) on-premises
VeloCloud heeft een kwetsbaarheid verholpen in VeloCloud Orchestrator (VCO) on-premises.
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Attackers are exploiting CVE-2026-93952 in certificate-authenticated VeloCloud Orchestrators, with some release trains still awaiting fixes.
Part of the PlainSec briefing for 2026-09-22