Arista has released urgent fixes for CVE-2026-93952, a CVSS 10.0 flaw in on-premises VeloCloud Orchestrator that attackers are already exploiting.
VCO is the control plane for an SD-WAN, configuring and monitoring every Edge device, policy and traffic flow. The bug is an improper input validation issue that lets a remote attacker reach privileged internal functions without any tenant or operator credentials.
Exposure is narrower than the score suggests but still common. An orchestrator is at risk when certificate-based authentication from a VeloCloud Edge is configured, and an attacker also needs network access to the VCO web interface plus the public half of an Edge’s authentication certificate. Unlike a July VCO flaw, this one does not hit every deployment by default.
Fixes are out for the 5.2 train at 5.2.3.16 and later and the 6.4 train at 6.4.2.8 and later. The 6.1 and 7.0 trains had no patch when the flaw was disclosed. Hosted and dedicated VCO were already remediated.
Arista published no definitive indicators of compromise, only hunting leads. Check VCO web access logs for unusual URL-like paths, encoded characters and high request rates, and watch for the files /usr/local/sbin/.vcnode.js, /usr/local/sbin/vc-sysmond, the unit vc-sysmon.service, the nginx header x-vc-opt and the addresses 142.93.149[.]77 and 104.248.126[.]159.
CISA added the flaw to its Known Exploited Vulnerabilities catalog and gave federal agencies three days to patch. Where that is impossible, restrict the VCO web interface to trusted administrative networks, watch outbound traffic, and review recent administrator activity for unexpected changes.
