Vulnerabilities · 4h ago

Arista VeloCloud Orchestrator Exploited Into Fleet Control

Arista said on September 22 that CVE-2026-93952 is being actively exploited against certificate-authenticated on-premises VeloCloud Orchestrators, with fixes already available for the 5.2 and 6.4 release trains and Hosted and Dedicated VCO, but still pending for 6.1 and 7.0. The flaw carries a CVSS 10.0 score.

The weakness sits in the trust model. If an attacker can reach the VCO web interface and has the public part of an Edge certificate, they can abuse internal functions without a normal login, compromise the orchestrator, and reach the Edge devices it manages. In plain terms, the controller is the trust broker for the fleet, so one server breach can become control of the managed network.

For operators running certificate-based VCO, the exposure is not a single-host event; it is the management plane for every enrolled Edge. That makes the pending-release trains and any deployment that still treats the orchestrator like an ordinary server the places to watch most closely.

CVE-2026-93952

NVD KEV

CVSS 10 CRITICAL: veloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. EPSS 0.4% (36th percentile).

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-09-22

Editions

Related stories