Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Arista Urges Immediate Patching of Exploited VCO Zero-Day

Remote attackers could trigger the critical-severity flaw to access privileged internal functionality.

Arista

Networking solutions provider Arista has released urgent patches for a critical-severity vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments that has been exploited as a zero-day.

VCO is a centralized management tool for configuring, monitoring, and orchestrating edge devices, policies, and traffic in Arista VeloCloud SD-WAN.

The exploited zero-day, tracked as CVE-2026-93952 (CVSS score of 10), is described as an improper input validation issue that could allow remote attackers to access privileged internal functionality.

Successful exploitation of the security defect could impact the confidentiality, integrity, and availability of the orchestrator and the data it manages.

“This issue was discovered externally and is known to be actively exploited,” Arista warns.

According to the company, the bug affects only VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom) and was resolved in VCO versions 5.2.3.16 and 6.4.2.8 in the 5.2.x and 6.1.x trains, respectively. Patches for other trains will also be released.

Advertisement. Scroll to continue reading.

“VCO is exposed if certificate-based authentication from the VeloCloud Edge to VCO is configured. Access to the public portion of the VeloCloud Edge authentication certificate is required. A successful attack requires network access to the VCO web interface. VCO tenant or operator credentials are not required for this exposure,” the company notes.

Arista says that deployments that limit access to the VCO web interface have a lower risk of exposure, but urges updating to a fixed release.

The company noted that there are no definitive indicators of compromise (IoCs), recommending administrators review VCO web access logs, backend application logs, and system logs for suspicious activity.

CVE-2026-93952 was added to CISA’s Known Exploited Vulnerabilities (KEV) list on Tuesday. In line with BOD 26-04’s recommendations, federal agencies were given three days to patch it.

Related: Critical F5 BIG-IP APM Vulnerability Exploited as a Zero-Day

Related: Check Point Patches Exploited Management Server Zero-Day

Related: Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity

Related: Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Doppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.

Delinea has appointed Timothy Regan as Chief Financial Officer.

Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.