"This issue was discovered externally and is known to be actively exploited," Arista Networks warned in a Tuesday advisory.
CVE-2026-93952: what the flaw is and how it can be exploited
Arista has tracked the vulnerability as CVE-2026-93952 and classed it as maximum severity. The flaw stems from an improper input validation weakness in VeloCloud Orchestrator (VCO) On-Prem deployments that have certificate-based authentication configured between the VeloCloud Edge and VCO. According to Arista, remote actors who can reach the VCO web interface and who have access to the public portion of a VeloCloud Edge authentication certificate can exploit the bug to access privileged internal VCO host functionality.
Arista describes the attacks as low complexity, not requiring privileges on the targeted system or any user interaction. The advisory explicitly states that VCO tenant or operator credentials are not required for successful exploitation.
Arista's patches and the affected VCO builds
Arista says it has already patched hosted VCO deployments running 5.2.3.16 or later and 6.4.2.8 or later. The company also committed to releasing security updates for on-premises VCO instances running 6.1.3.7 and below and 7.0.0.2 and below. Operators of affected on-prem deployments who cannot immediately apply patches were advised to restrict access to the VCO web interface to administrative networks while updates are rolled out.
The vendor noted that hosted deployments have already been remediated for the versions listed above.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildCISA response and the federal deadline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog on Tuesday and ordered U.S. federal civilian executive branch agencies to secure their networks by Friday, September 25. The catalog listing and the agency order raise the urgency for federal operators to apply available mitigations or patches within the specified timeframe.
Indicators of compromise and recommended operational steps
While patches are distributed, Arista provided a set of candidate detection and mitigation actions for administrators and security teams. Recommended steps include:
- Restricting access to the VCO web interface to administrative networks;
- Reviewing recent administrator activity for unusual changes;
- Monitoring for connections from known malicious IP addresses — specifically blocking 142[.]93.149.77 and 104[.]248.126.159;
- Reviewing VCO web access logs for suspicious indicators such as requests containing encoded characters, unusual URL-like path components, references to local or internal services, or high request rates;
- Checking nginx logs for the x-vc-opt HTTP header and watching for unexpected outbound HTTP or HTTPS activity originating from the VCO host.
Arista also advised that if compromise is suspected, operators should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible, and to contact the Arista Networks Technical Assistance Center (TAC) for additional assistance.
Context inside Arista's recent security fixes
CVE-2026-93952 is the latest in a string of zero-day fixes Arista has released this year. Earlier in 2026 the company patched two other actively exploited zero-days: CVE-2026-7473 in May and CVE-2026-16812 in July, which affected the Extensible Operating System (EOS) and on-premises VeloCloud Orchestrator deployments respectively. The recurrence of high-severity on-prem VCO issues makes the present advisory part of a pattern Arista has already been addressing during the year.
Arista is a Fortune 500 company with more than 10,000 customers worldwide, a scale that helps explain why rapid remediation and a public advisory were prioritized.
How security teams, federal agencies, and enterprise customers should respond
Security teams and network operators should prioritize patching and, where immediate patching is impractical, apply the network-access restrictions Arista recommends. Teams should also search logs for the specific suspicious patterns Arista lists and block the two IPs Arista singled out.
Federal civilian executive branch agencies are under a CISA order to secure networks by September 25; that deadline requires agencies to ensure either patching or compensating controls are in place within the timeframe CISA set.
Enterprise customers running on-prem VCO instances should confirm whether their builds fall into the ranges Arista named (6.1.3.7 and below or 7.0.0.2 and below) and schedule updates urgently, including preserving forensic artifacts if compromise is suspected and contacting Arista TAC as needed.
Arista’s advisory combines a concrete technical description with immediate operational guidance: accessible certificates and network access to the VCO web interface are the keys attackers are exploiting, and the company has already patched many hosted environments while scheduling patches for remaining on-prem releases. With CISA’s catalog listing and the federal deadline set for September 25, the next 48–72 hours will determine how quickly affected installations close this exposure.




