INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Arista Patches VeloCloud Orchestrator Zero-Day Exploit
| 2026-09-23 08:33 CRITICAL MEDIUM EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A zero-day flaw, tracked as CVE-2026-93952, was discovered and is being actively exploited, affecting VeloCloud Orchestrator (VCO) On-Prem deployments. Arista Networks has released security patches for hosted deployments running VCO [IOC HIDDEN • LOGIN REQUIRED] or later and VCO 6.4.2.8 or later, as well as instances running 6.1.3.7 and below and 7.0.0.2 and below. The vulnerability stems from an improper input validation weakness in certificate-based authentication between the VeloCloud Edge and VCO Orchestrator, allowing remote threat actors to access privileged internal VCO host functionality with low-complexity attacks that don't require privileges or user interaction. As of September 23, Arista has patched affected deployments, while the US Cybersecurity and Infrastructure Security Agency has added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog, ordering federal agencies to secure their networks by Friday, September 25.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-93952, CVE-2026-16812 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
vc•••••.service
vc•••••.js
104.248.•••.•••
142.93.•••.•••
dc78e2••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-93952CVE-2026-93952
CVE-2026-16812CVE-2026-16812
CVE-2026-7473CVE-2026-7473
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
Sep 22, 2026
Threat actors exploited a previously unknown vulnerability in the Arista VeloCloud Orchestrator to gain unauthorized access.
September 22
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages Edge devices in a VeloCloud SD-WAN.
Click on any entity below to view its context and source!
infrastructure
5.2
As of September 22,
fixed releases
are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains.
infrastructure
6.1
As of September 22,
fixed releases
are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains.
infrastructure
6.4
As of September 22,
fixed releases
are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains.
infrastructure
7.0
As of September 22,
fixed releases
are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains.
general_metric
5.2 release trains
As of September 22,
fixed releases
are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains.
general_metric
6.4 release trains
As of September 22,
fixed releases
are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains.
The July flaw did not depend on settings: VCO was exposed to it by default, and no configuration could prevent that.
Fixed Releases
As of September 22, these are the affected releases in each train, the releases that fix them, and the releases that fixed the July flaw:
Train
Affected by CVE-2026-93952
Fixed in
July flaw…
general_metric
6.1 trains
As of September 22,
fixed releases
are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains.
organisation
Arista
Swati Khandelwal
Sep 22, 2026
Vulnerability / Network Security
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22.
organisation
VCO
Swati Khandelwal
Sep 22, 2026
Vulnerability / Network Security
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22.
organisation
Vulnerability / Network Security
Swati Khandelwal
Sep 22, 2026
Vulnerability / Network Security
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22.
general_metric
22 Sep
Swati Khandelwal
Sep 22, 2026
Vulnerability / Network Security
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22.
2026/09/23
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments, specifically those configured with certificate-based authentication from the VeloCloud Edge to VCO.
Click on any entity below to view its context and source!
organisation
CVE-2026-93952
The exploited zero-day, tracked as CVE-2026-93952 (CVSS score of 10), is described as an improper input validation issue that could allow remote attackers to access privileged internal functionality.
organisation
KEV
CVE-2026-93952 was added to CISA’s Known Exploited Vulnerabilities (
KEV
) list on Tuesday.
organisation
the VeloCloud Edge
Tracked as
CVE-2026-93952
, this maximum-severity flaw stems from an improper input validation weakness and affects VCO deployments where certificate-based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured.
“VCO is exposed if certificate-based authentication from the VeloCloud Edge to VCO is configured.
Arista said an orchestrator is exposed if "certificate based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured."
infrastructure
5.2.3
According to the company, the bug affects only VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom) and was resolved in VCO versions 5.2.3.16 and 6.4.2.8 in the 5.2.x and 6.1.x trains, respectively.
"
Arista says that it has already patched hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later and that it will also release security patches for VCO instances running 6.1.3.7 and below and 7.0.0.2 and below.
…flaw:
Train
Affected by CVE-2026-93952
Fixed in
July flaw (CVE-2026-16812) fixed in
5.2
5.2.3.15 and earlier
5.2.3.16 and later
5.2.3.14
6.1
6.1.3.7 and earlier
No fix yet
6.1…
infrastructure
6.4.2
According to the company, the bug affects only VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom) and was resolved in VCO versions 5.2.3.16 and 6.4.2.8 in the 5.2.x and 6.1.x trains, respectively.
"
Arista says that it has already patched hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later and that it will also release security patches for VCO instances running 6.1.3.7 and below and 7.0.0.2 and below.
…5.2.3.16 and later
5.2.3.14
6.1
6.1.3.7 and earlier
No fix yet
6.1.3.4
6.4
6.4.2.7 and earlier
6.4.2.8 and later
6.4.2.4
7.0
7.0.0.2 and earlier
No fix yet
infrastructure
5.2
According to the company, the bug affects only VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom) and was resolved in VCO versions 5.2.3.16 and 6.4.2.8 in the 5.2.x and 6.1.x trains, respectively.
…s that fixed the July flaw:
Train
Affected by CVE-2026-93952
Fixed in
July flaw (CVE-2026-16812) fixed in
5.2
5.2.3.15 and earlier
5.2.3.16 and later
5.2.3.14
6.1
6.1.3.7 and earlier
No fix yet…
infrastructure
6.1
According to the company, the bug affects only VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom) and was resolved in VCO versions 5.2.3.16 and 6.4.2.8 in the 5.2.x and 6.1.x trains, respectively.
…July flaw (CVE-2026-16812) fixed in
5.2
5.2.3.15 and earlier
5.2.3.16 and later
5.2.3.14
6.1
6.1.3.7 and earlier
No fix yet
6.1.3.4
6.4
6.4.2.7 and earlier
6.4.2.8 and later…
organisation
Arista
"
Arista says that it has already patched hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later and that it will also release security patches for VCO instances running 6.1.3.7 and below and 7.0.0.2 and below.
Networking solutions provider Arista has released urgent patches for a critical-severity vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments that has been exploited as a zero-day.
infrastructure
6.1.3
"
Arista says that it has already patched hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later and that it will also release security patches for VCO instances running 6.1.3.7 and below and 7.0.0.2 and below.
…(CVE-2026-16812) fixed in
5.2
5.2.3.15 and earlier
5.2.3.16 and later
5.2.3.14
6.1
6.1.3.7 and earlier
No fix yet
6.1.3.4
6.4
6.4.2.7 and earlier
6.4.2.8 and later
6.4.2.…
infrastructure
7.0.0
"
Arista says that it has already patched hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later and that it will also release security patches for VCO instances running 6.1.3.7 and below and 7.0.0.2 and below.
…5.2.3.16 and later
5.2.3.14
6.1
6.1.3.7 and earlier
No fix yet
6.1.3.4
6.4
6.4.2.7 and earlier
6.4.2.8 and later
6.4.2.4
7.0
7.0.0.2 and earlier
No fix yet
infrastructure
6.4
…5.2.3.16 and later
5.2.3.14
6.1
6.1.3.7 and earlier
No fix yet
6.1.3.4
6.4
6.4.2.7 and earlier
6.4.2.8 and later
6.4.2.4
7.0
7.0.0.2 and earlier
No fix yet
infrastructure
7.0
…5.2.3.16 and later
5.2.3.14
6.1
6.1.3.7 and earlier
No fix yet
6.1.3.4
6.4
6.4.2.7 and earlier
6.4.2.8 and later
6.4.2.4
7.0
7.0.0.2 and earlier
No fix yet
organisation
VCO
Networking solutions provider Arista has released urgent patches for a critical-severity vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments that has been exploited as a zero-day.
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments.
organisation
Networks
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments.
organisation
VeloCloud Orchestrator
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments.
organisation
Microsoft
Related:
Critical F5 BIG-IP APM Vulnerability Exploited as a Zero-Day
Related:
Check Point Patches Exploited Management Server Zero-Day
Related:
Nightmare Eclipse Drops New Microsoft Defender Exploit
organisation
Flaws Across FMC
After Revealing Identity
Related:
Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard
organisation
Nexus
After Revealing Identity
Related:
Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard
organisation
Arista Networks
Arista Networks is a Fortune 500 company and one of the largest United States corporations by revenue, with more than 10,000 customers worldwide.
victims
10,000 customers
Arista Networks is a Fortune 500 company and one of the largest United States corporations by revenue, with more than 10,000 customers worldwide.
organisation
Extensible Operating System
Since the start of the year, Arista patched two other zero-day flaws (
CVE-2026-7473
in May and
CVE-2026-16812
in July) that were being actively exploited in attacks and affected Extensible Operating System (EOS) and on-premises VeloCloud Orchestrator deployments, respectively.
organisation
EOS
Since the start of the year, Arista patched two other zero-day flaws (
CVE-2026-7473
in May and
CVE-2026-16812
in July) that were being actively exploited in attacks and affected Extensible Operating System (EOS) and on-premises VeloCloud Orchestrator deployments, respectively.
organisation
IP
Indicators of compromise
While security patches are being deployed, admins should restrict access to the VCO web interface to administrative networks, review recent administrator activity for unusual changes, and monitor for connections from known malicious IP addresses.
Monitor the VCO for access from known malicious IP addresses.
organisation
Admins
Admins should review VCO web access logs for suspicious activity, such as requests containing encoded characters, unusual URL-like path components, references to local or internal services, or high request rates.
organisation
the Arista Networks Technical Assistance Center
"If compromise is suspected, operators should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible," it added, and advised customers to contact the Arista Networks Technical Assistance Center (TAC) if they need additional assistance.
organisation
TAC
"If compromise is suspected, operators should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible," it added, and advised customers to contact the Arista Networks Technical Assistance Center (TAC) if they need additional assistance.
Customers on an unsupported release train can contact Arista's Technical Assistance Center (TAC) about upgrade options.
organisation
Technical Assistance Center
Customers on an unsupported release train can contact Arista's Technical Assistance Center (TAC) about upgrade options.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
Edges
Only orchestrators set up to authenticate their Edges with certificates are exposed.
organisation
Hosted
Arista has already patched the Hosted and Dedicated versions of VCO.
organisation
The Hacker News
The Hacker News has contacted Arista for comment.
organisation
Which Deployments Are Exposed
VeloCloud Edges
Which Deployments Are Exposed
VeloCloud Edges can authenticate to the orchestrator in one of
three modes
.
organisation
Certificate Required modes
In Certificate Acquire and Certificate Required modes, it uses a certificate issued by the orchestrator.
organisation
Limit
Limit access to the VCO web interface to trusted administrative networks.
Friday, September 25
The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog, ordering federal agencies to secure their networks by September 25.
Click on any entity below to view its context and source!
attribution
CVE-2026-93952
The U.S. Cybersecurity and Infrastructure Security Agency
has also added CVE-2026-93952
to its Known Exploited Vulnerabilities catalog on Tuesday and ordered U.S. federal civilian executive branch agencies to secure their networks
by Friday, September 25
.
tactic
T1588.006 - Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency
has also added CVE-2026-93952
to its Known Exploited Vulnerabilities catalog on Tuesday and ordered U.S. federal civilian executive branch agencies to secure their networks
by Friday, September 25
.
attribution
Known Exploited
The U.S. Cybersecurity and Infrastructure Security Agency
has also added CVE-2026-93952
to its Known Exploited Vulnerabilities catalog on Tuesday and ordered U.S. federal civilian executive branch agencies to secure their networks
by Friday, September 25
.
Tactical Metrics
Metrics
infrastructure
5.2.3
Software Version
Click for context!
According to the company, the bug affects only VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom) and was resolved in VCO versions 5.2.3.16 and 6.4.2.8 in the 5.2.x and 6.1.x trains, respectively.
"
Arista says that it has already patched hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later and that it will also release security patches for VCO instances running 6.1.3.7 and below and 7.0.0.2 and below.
…flaw:
Train
Affected by CVE-2026-93952
Fixed in
July flaw (CVE-2026-16812) fixed in
5.2
5.2.3.15 and earlier
5.2.3.16 and later
5.2.3.14
6.1
6.1.3.7 and earlier
No fix yet
6.1…
Metrics
infrastructure
6.4.2
Software Version
According to the company, the bug affects only VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom) and was resolved in VCO versions 5.2.3.16 and 6.4.2.8 in the 5.2.x and 6.1.x trains, respectively.
"
Arista says that it has already patched hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later and that it will also release security patches for VCO instances running 6.1.3.7 and below and 7.0.0.2 and below.
…5.2.3.16 and later
5.2.3.14
6.1
6.1.3.7 and earlier
No fix yet
6.1.3.4
6.4
6.4.2.7 and earlier
6.4.2.8 and later
6.4.2.4
7.0
7.0.0.2 and earlier
No fix yet
Metrics
infrastructure
5.2
Software Version
According to the company, the bug affects only VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom) and was resolved in VCO versions 5.2.3.16 and 6.4.2.8 in the 5.2.x and 6.1.x trains, respectively.
As of September 22,
fixed releases
are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains.
…s that fixed the July flaw:
Train
Affected by CVE-2026-93952
Fixed in
July flaw (CVE-2026-16812) fixed in
5.2
5.2.3.15 and earlier
5.2.3.16 and later
5.2.3.14
6.1
6.1.3.7 and earlier
No fix yet…
Metrics
infrastructure
6.1
Software Version
According to the company, the bug affects only VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom) and was resolved in VCO versions 5.2.3.16 and 6.4.2.8 in the 5.2.x and 6.1.x trains, respectively.
As of September 22,
fixed releases
are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains.
…July flaw (CVE-2026-16812) fixed in
5.2
5.2.3.15 and earlier
5.2.3.16 and later
5.2.3.14
6.1
6.1.3.7 and earlier
No fix yet
6.1.3.4
6.4
6.4.2.7 and earlier
6.4.2.8 and later…
Metrics
victims
10,000
Customers
Arista Networks is a Fortune 500 company and one of the largest United States corporations by revenue, with more than 10,000 customers worldwide.
Metrics
infrastructure
6.1.3
Software Version
"
Arista says that it has already patched hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later and that it will also release security patches for VCO instances running 6.1.3.7 and below and 7.0.0.2 and below.
…(CVE-2026-16812) fixed in
5.2
5.2.3.15 and earlier
5.2.3.16 and later
5.2.3.14
6.1
6.1.3.7 and earlier
No fix yet
6.1.3.4
6.4
6.4.2.7 and earlier
6.4.2.8 and later
6.4.2.…
Metrics
infrastructure
7.0.0
Software Version
"
Arista says that it has already patched hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later and that it will also release security patches for VCO instances running 6.1.3.7 and below and 7.0.0.2 and below.
…5.2.3.16 and later
5.2.3.14
6.1
6.1.3.7 and earlier
No fix yet
6.1.3.4
6.4
6.4.2.7 and earlier
6.4.2.8 and later
6.4.2.4
7.0
7.0.0.2 and earlier
No fix yet
Metrics
infrastructure
6.4
Software Version
As of September 22,
fixed releases
are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains.
…5.2.3.16 and later
5.2.3.14
6.1
6.1.3.7 and earlier
No fix yet
6.1.3.4
6.4
6.4.2.7 and earlier
6.4.2.8 and later
6.4.2.4
7.0
7.0.0.2 and earlier
No fix yet
Metrics
infrastructure
7.0
Software Version
As of September 22,
fixed releases
are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains.
…5.2.3.16 and later
5.2.3.14
6.1
6.1.3.7 and earlier
No fix yet
6.1.3.4
6.4
6.4.2.7 and earlier
6.4.2.8 and later
6.4.2.4
7.0
7.0.0.2 and earlier
No fix yet
Intelligence Sources
SecurityWeek
2026-09-23
The Hacker News
2026-09-22
BleepingComputer
2026-09-23
Arista patches actively exploited VeloCloud Orchestrator zero-day
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:03
Comprehensive Tactical Telemetry
Highly Correlated Entities
27x
organisation
Identified Entity
CVE-2026-93952
entity
8x
infrastructure
Software Version
5.2.3
version
5x
timeline
Temporal Reference
26-04
date
4x
attribution
Attributing Entity
CISA’s Known Exploited
authority
3x
vulnerability
Exploited CVE
CVE-2026-93952
cve
3x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
vulnerability
CVSS Score
10
score
2x
general metric
Release Trains
5
release trains
Contextual Telemetry
Context Block
6 METRICS
target region
Target Country
United States
country
general metric
Fortune
500
fortune
victims
Customers
10,000
customers
general metric
Trains
6
trains
general metric
Score
3
score
general metric
Sep
22
sep
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.