Arista assigned a CVSS 3.1 score of 10.0 to CVE-2026-93952, a new vulnerability in on‑premises VeloCloud Orchestrator (VCO) that the company says "was discovered externally and is known to be actively exploited."
CVE-2026-93952: exposure and attack prerequisites
The flaw, tracked as CVE-2026-93952, targets on‑premises VeloCloud Orchestrator — the server that manages VeloCloud Edge devices in a VeloCloud SD‑WAN deployment. Arista warned on September 22 that a successful exploitation may compromise the orchestrator and the data it manages, and that a compromised VCO may also give attackers access to the Edge devices it controls.
Arista said the vulnerability "may allow a remote attacker with no login access to privilege internal functions and affect the VCO host," but it is not universally exploitable across all deployments. The attack requires three conditions: the orchestrator must be set up to authenticate Edges with certificates, the attacker needs network access to the VCO web interface, and the attacker needs the public part of an Edge's authentication certificate.
VeloCloud Edges can authenticate to the orchestrator in three modes: Certificate Deactivated (using a pre‑shared key), Certificate Acquire, and Certificate Required (the latter two use certificates issued by the orchestrator). Arista stated an orchestrator is exposed if "certificate based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured," but it did not specify which of the certificate modes that phrase covers.
Affected release trains, patches released, and outstanding fixes
As of September 22, Arista reported that fixed releases are available for the 5.2 and 6.4 release trains; fixes were not yet available for the 6.1 and 7.0 trains. Arista has already patched both the Hosted and Dedicated versions of VCO. The vendor also noted that the affected releases include those that addressed a different VCO flaw Arista reported as exploited in July — a July flaw that, by contrast, did not depend on configuration and exposed VCO by default.
Arista added that fixes for supported but still affected trains are forthcoming and will be added to its advisory when ready. Customers on unsupported release trains were advised to contact Arista's Technical Assistance Center (TAC) about upgrade options.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleIf you cannot upgrade yet: Arista's interim mitigations
Until administrators can install a fixed release, Arista recommends practical network and monitoring controls intended to reduce risk and speed detection. The vendor's guidance includes:
- Limit access to the VCO web interface to trusted administrative networks.
- Monitor the VCO for access from known malicious IP addresses.
- Monitor for unexpected outbound network traffic from the VCO host and consider blocking outbound ports that are not required for normal operation.
- Monitor for backdoor daemons and webshells, and review recent administrator activity for unexpected changes.
Indicators of compromise and immediate incident steps
Arista said no single indicator proves exploitation through this flaw, but it published specific artifacts and behaviors to check for. Administrators should examine VCO web access logs for requests with unusual URL‑like paths, encoded characters, references to local or internal services, or high request rates. The vendor listed concrete file and log indicators:
- Files: /usr/local/sbin/.vcnode.js and /usr/local/sbin/vc-sysmond
- Service unit: /etc/systemd/system/vc-sysmon.service
- MD5 (vc-sysmond): dc78e206eaeadec59fc5801fe4556bd0
- HTTP header seen in nginx logs: x-vc-opt
- IP addresses: 142.93.149[.]77 and 104.248.126[.]159
If any of these indicators are found, Arista advises preserving the state of the VCO and contacting TAC or your Arista account team. Where compromise is suspected, customers should save the VCO's web access, backend application, system, and database logs and file‑system timestamps before taking remediation steps, when practical. After upgrading, Arista also recommends incident response actions such as rotating credentials, reviewing administrator activity, validating the state of managed Edge devices, and restoring or replacing the orchestrator from trusted sources.
What this means for VeloCloud administrators, incident responders, and procurement/network teams
VeloCloud administrators: Check whether your orchestrator is configured for certificate‑based Edge authentication and restrict web interface access immediately. Follow Arista's file, header, and IP indicators to hunt for signs of compromise.
Incident responders: Preserve logs and filesystem timestamps before remediation where possible, contact Arista TAC if indicators are present, and plan post‑upgrade actions — credential rotation and verification of managed Edge devices are specific steps Arista recommends.
Procurement and network teams: Confirm which VCO release trains your deployment uses. If you run 6.1 or 7.0 train instances, plan for an imminent update once Arista publishes fixes; customers on unsupported trains should engage TAC about upgrade options.
Arista's advisory leaves two operational facts central to immediate risk calculations: the vulnerability is being actively exploited, and fixes exist today for some, but not all, release trains. Administrators with certificate‑based Edge authentication and reachable VCO web interfaces should assume heightened risk until their orchestrators are patched or adequately isolated, and act on the vendor's detection and preservation guidance.




