Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.5
CVE-2026-93952: Arista VeloCloud Orchestrator allows remote access to internal functions
CVE-2026-93952 · published 5 days ago · actively exploited
Summary
The on‑premise VeloCloud Orchestrator can be tricked into accepting crafted input, letting a remote attacker reach privileged features. This could let the attacker view, alter, or disrupt the system and the data it manages. Install the latest vendor update and limit network access to the Orchestrator while monitoring for unusual activity.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| arista networks | velocloud orchestrator (vco) on-prem | <= 5.2.3.15 |
| arista | velocloud orchestrator | All versions |
| arista | velocloud_orchestrator |
>= 5.2.0, < 5.2.3.16 >= 6.1.0, <= 6.1.3.7 >= 6.4.0, < 6.4.2.8 >= 7.0.0, <= 7.0.0.2 cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:* |
Original advisory text
Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
References
- https://www.arista.com/en/support/advisories-notices/security-advisory/24765-sec... Mitigation Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-... US Government Resource
Severity
9.5
Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
EPSS <1%
Type
CWE-20Improper Input Validation
Timeline
Published22 Sep 2026
Updated27 Sep 2026
First seen22 Sep 2026
Track software like this
Free during beta