INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Arista Patches VeloCloud Orchestrator Zero-Day Exploit

| 2026-09-23 08:33 CRITICAL MEDIUM EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A zero-day flaw, tracked as CVE-2026-93952, was discovered and is being actively exploited, affecting VeloCloud Orchestrator (VCO) On-Prem deployments. Arista Networks has released security patches for hosted deployments running VCO [IOC HIDDEN • LOGIN REQUIRED] or later and VCO 6.4.2.8 or later, as well as instances running 6.1.3.7 and below and 7.0.0.2 and below. The vulnerability stems from an improper input validation weakness in certificate-based authentication between the VeloCloud Edge and VCO Orchestrator, allowing remote threat actors to access privileged internal VCO host functionality with low-complexity attacks that don't require privileges or user interaction. As of September 23, Arista has patched affected deployments, while the US Cybersecurity and Infrastructure Security Agency has added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog, ordering federal agencies to secure their networks by Friday, September 25.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-93952, CVE-2026-16812 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

vc•••••.service
vc•••••.js
104.248.•••.•••
142.93.•••.•••
dc78e2••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-93952CVE-2026-93952 CVE-2026-16812CVE-2026-16812 CVE-2026-7473CVE-2026-7473
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎Sep 22, 2026
Threat actors exploited a previously unknown vulnerability in the Arista VeloCloud Orchestrator to gain unauthorized access.
‎September 22
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages Edge devices in a VeloCloud SD-WAN.
infrastructure 5.2
infrastructure 6.1
infrastructure 6.4
infrastructure 7.0
general_metric 5.2 release trains
general_metric 6.4 release trains
general_metric 6.1 trains
organisation Arista
organisation VCO
organisation Vulnerability / Network Security
general_metric 22 Sep
‎2026/09/23
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments, specifically those configured with certificate-based authentication from the VeloCloud Edge to VCO.
organisation CVE-2026-93952
organisation KEV
organisation the VeloCloud Edge
infrastructure 5.2.3
infrastructure 6.4.2
infrastructure 5.2
infrastructure 6.1
organisation Arista
infrastructure 6.1.3
infrastructure 7.0.0
infrastructure 6.4
infrastructure 7.0
organisation VCO
organisation Networks
organisation VeloCloud Orchestrator
organisation Microsoft
organisation Flaws Across FMC
organisation Nexus
organisation Arista Networks
victims 10,000 customers
organisation Extensible Operating System
organisation EOS
organisation IP
organisation Admins
organisation the Arista Networks Technical Assistance Center
organisation TAC
organisation Technical Assistance Center
organisation NFL
organisation CHANEL
organisation Edges
organisation Hosted
organisation The Hacker News
organisation Which Deployments Are Exposed VeloCloud Edges
organisation Certificate Required modes
organisation Limit
‎Friday, September 25
The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog, ordering federal agencies to secure their networks by September 25.
attribution CVE-2026-93952
tactic T1588.006 - Vulnerabilities
attribution Known Exploited
Tactical Metrics
Metrics
infrastructure
‎5.2.3
Software Version
Metrics
infrastructure
‎6.4.2
Software Version
Metrics
infrastructure
‎5.2
Software Version
Metrics
infrastructure
‎6.1
Software Version
Metrics
victims
10,000
Customers
Metrics
infrastructure
‎6.1.3
Software Version
Metrics
infrastructure
‎7.0.0
Software Version
Metrics
infrastructure
‎6.4
Software Version
Metrics
infrastructure
‎7.0
Software Version
Intelligence Sources