A maximum-severity flaw affecting VeloCloud Orchestrator (VCO) On-Prem installations has prompted Arista Networks to deploy security patches. The vulnerability, designated CVE-2026-93952, stems from inadequate input validation in systems where certificate-based authentication between VeloCloud Edge and VeloCloud Orchestrator is enabled.
VCO serves as a centralized management platform enabling administrators to configure, monitor, and oversee VeloCloud SD-WANs (Software-Defined Wide Area Networks) alongside their associated edge infrastructure.
Attackers can leverage this flaw to gain access to privileged internal VCO host functions through low-complexity attacks that require neither system privileges nor user interaction. The exploit demands only network access to the VCO web interface and knowledge of the public portion of the VeloCloud Edge authentication certificate.
This issue was discovered externally and is known to be actively exploited. Access to the public portion of the VeloCloud Edge authentication certificate is required. A successful attack requires network access to the VCO web interface. VCO tenant or operator credentials are not required for this exposure.
Arista Networks
Arista has already secured hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later. The company plans to release patches for VCO instances operating version 6.1.3.7 and below as well as 7.0.0.2 and below.
The U.S. Cybersecurity and Infrastructure Security Agency incorporated CVE-2026-93952 into its Known Exploited Vulnerabilities catalog on Tuesday and mandated that U.S. federal civilian executive branch agencies remediate their systems by Friday, September 25.
Indicators of compromise
While patches roll out, administrators should implement several defensive measures. Limiting VCO web interface access to administrative networks, examining recent administrator activity for unexpected modifications, and tracking connections originating from identified malicious IP addresses represent immediate priorities.
Reviewing VCO web access logs for anomalous patterns is essential. Administrators should look for requests featuring encoded characters, atypical URL-like path segments, references to local or internal services, or elevated request volumes.
Arista recommends blocking traffic from IP addresses 142[.]93.149.77 and 104[.]248.126.159. Security teams should also inspect nginx logs for the x-vc-opt HTTP header and investigate any unexpected outbound HTTP or HTTPS connections originating from the VCO host.
If compromise is suspected, operators should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible.
Arista Networks
Organizations requiring further guidance should reach out to the Arista Networks Technical Assistance Center (TAC).
This marks the third zero-day vulnerability Arista has patched since the beginning of the year. CVE-2026-7473, disclosed in May, affected Extensible Operating System (EOS) deployments and was under active exploitation. Similarly, CVE-2026-16812, patched in July, targeted on-premises VeloCloud Orchestrator installations and was also being exploited.
Arista Networks operates as a Fortune 500 corporation and ranks among the largest U.S. companies by revenue, serving more than 10,000 customers globally.