TL;DR
On September 22, 2026, Arista Networks warned of active attacks against a critical VeloCloud vulnerability. Tracked as CVE-2026-93952, the flaw earns a maximum CVSS rating of 10.0. The vendor confirmed that threat actors actively exploit this security defect in the wild.
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy It Matters
Enterprise SD-WAN controllers serve as the central backbone for distributed corporate networks. Industry estimates indicate that thousands of global enterprise branches rely on VeloCloud infrastructure. Therefore, compromising the orchestrator platform exposes vital communication channels to immediate takeover.
The vendor issued an urgent warning regarding the threat. Arista confirmed, “This issue was discovered externally and is known to be actively exploited.” While attackers actively compromise live systems, researchers have not confirmed any public proof-of-concept code. Successful attacks allow adversaries to alter device configurations across entire organizations. Consequently, security teams must treat this critical VeloCloud vulnerability as an emergency maintenance priority. Unpatched systems give unauthorized intruders complete administrative control over managed assets.
How The Attack Works
The weakness stems from improper input validation within the on-premises orchestrator software. In the official Arista security advisory, engineers explained the core mechanism. The advisory states, “VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host.”
The attack requires specific network conditions to succeed. First, an environment must configure certificate-based authentication between edge appliances and the orchestrator. Attackers also require access to the public portion of the edge authentication certificate. Next, the adversary sends untrusted input directly to the web interface. Because the system lacks proper input filtering, the input bypasses authorization controls. An attacker requires no existing operator credentials to execute this exploit. Furthermore, intrusions often install backdoor services, such as a malicious script named vcnode.js. Adversaries also create persistence files under system directories to maintain control.
Affected Versions
This security flaw affects multiple release trains of VeloCloud Orchestrator on-prem. Specifically, vulnerable builds include versions 5.2.3.15 and earlier in the 5.2 train. It also impacts versions 6.1.3.7 and below, 6.4.2.7 and below, and 7.0.0.2 and below. In contrast, cloud-hosted versions of the platform have already received automated security patches. Standard Arista switches running EOS remain unaffected by this flaw.
Patch Or Mitigation Steps
Administrators must immediately apply the official vendor updates to protect their networks. Arista released remediated software builds, including version 5.2.3.16 and version 6.4.2.8. Organizations running other unsupported release trains must contact customer support for upgrade options.
If applying immediate patches is impossible, operators should enforce strict access controls. Administrators must restrict web interface access to trusted internal subnets. Additionally, security teams should inspect server logs for unexpected activity. Operators should check nginx access logs for anomalous headers such as x-vc-opt. Investigating outbound connections to suspicious IP addresses helps identify early signs of compromise. Ultimately, updating software remains the only reliable method to eliminate this exploited VeloCloud vulnerability.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!