Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2988+ Articles
168+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
NEWS

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

Arista disclosed CVE-2026-93952, a CVSS 10.0 pre-auth privilege escalation in VeloCloud Orchestrator, already under active exploitation.

Dylan H.

News Desk

September 22, 2026
2 min read

Maximum-Severity Flaw Already Being Exploited

Attackers are actively exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO) — the management server behind VeloCloud's SD-WAN Edge devices — Arista disclosed on September 22, 2026. The vulnerability, tracked as CVE-2026-93952, carries a CVSS score of 10.0.


Vulnerability Summary

FieldDetails
CVE IDCVE-2026-93952
CVSS Score10.0 (Critical)
Vulnerability TypeRemote privilege escalation, no login required
Disclosed ByArista Networks
Exploitation StatusConfirmed active exploitation

Arista states the flaw "was discovered externally and is known to be actively exploited," and allows a remote attacker with no login access to privilege internal functions and affect the VCO host.


Affected Versions and Patches

BranchVulnerable VersionsPatch Status
5.25.2.3.15 and earlierFixed in 5.2.3.16+
6.16.1.3.7 and earlierNo patch yet
6.46.4.2.7 and earlierFixed in 6.4.2.8+
7.07.0.0.2 and earlierNo patch yet

Arista's Hosted and Dedicated VCO offerings have already been patched by the vendor directly.


Attack Requirements

Exploitation requires network access to the VCO web interface, plus the public part of an Edge device's authentication certificate. Only orchestrators configured for certificate-based Edge authentication are vulnerable — deployments using other authentication modes are not affected by this specific flaw.


Indicators of Compromise

Arista's guidance flags the following for defenders hunting active exploitation:

  • Suspicious outbound traffic to 142.93.149.77 and 104.248.126.159
  • Presence of .vcnode.js on the orchestrator filesystem
  • Unexpected vc-sysmond process activity
  • The x-vc-opt HTTP header appearing in web interface logs

Mitigation

  • Apply the patched release for your branch immediately (5.2.3.16+ / 6.4.2.8+); monitor for fixes on 6.1 and 7.0
  • Restrict VCO web interface access to trusted administrative networks only
  • Monitor for the IOCs above across web and system logs
  • If compromise is suspected: rotate credentials and consider orchestrator replacement per incident response procedures
  • Review whether certificate-based Edge authentication is required for your deployment, or whether an alternate auth mode can reduce exposure in the interim

Sources

  • The Hacker News — New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
#VeloCloud#Arista#SD-WAN#CVE-2026-93952#Active Exploitation#Cloud Security

Related Articles

Arista Patches VeloCloud Orchestrator Zero-Day Exploited in Attacks

Arista Networks has released an emergency patch for a maximum-severity command injection zero-day in on-premises VeloCloud Orchestrator deployments that is being actively exploited in the wild.

5 min read

Cisco Catalyst SD-WAN Controller Auth Bypass Actively

Cisco has patched a maximum-severity authentication bypass flaw in its Catalyst SD-WAN Controller that has already been exploited in limited attacks....

5 min read

Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available

Cisco has disclosed active exploitation of CVE-2026-20245, a high-severity vulnerability in Catalyst SD-WAN Manager with a CVSS score of 7.8. No patch is…

6 min read
Back to all News