Threat Landscape

Arista VeloCloud CVE-2026-93952 is CVSS 10.0. On-prem Orchestrator — and it is ITW.

CVE-2026-93952 (CVSS 3.1 10.0): on-prem VeloCloud Orchestrator (VCO) may let a remote attacker reach privileged internal functions and impact the VCO host when certificate-based Edge→VCO auth is configured. Arista: discovered externally and known to be actively exploited. Fixed: 5.2.3.16+ / 6.4.2.8+. Hosted and Dedicated already patched. Victim count: Undisclosed.

Sep 22, 2026 · 3 min read

SD-WAN control plane, max score, vendor-confirmed exploitation. That is the board brief.

On September 22 Arista published Security Advisory 0183 for CVE-2026-93952 in on-prem VeloCloud Orchestrator (formerly Broadcom VeloCloud). CVSS v3.1 base: 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). CVSS v4.0 base: 9.5. CWE-20 Improper Input Validation. Bug trackers: BUG1907167, BUG1937417. Company wording: the issue may allow a remote attacker to access privileged internal functionality and impact the VCO host; successful exploitation may compromise confidentiality, integrity, and availability of the orchestrator and data it manages. Compromised VCO may also open a path to managed Edge devices.

Required config for exposure (Arista): certificate-based authentication from VeloCloud Edge to VCO is configured; the attacker needs network access to the VCO web interface and the public portion of an Edge authentication certificate. Tenant or operator credentials are not required. Deployments that keep the VCO web UI on trusted admin networks only reduce exposure. Hosted, including Dedicated, VCO versions were impacted and have already been patched.

Affected on-prem trains per advisory: 5.2.3.15 and below, 6.1.3.7 and below, 6.4.2.7 and below, 7.0.0.2 and below. Fixed as of Sep 22: VCO 5.2.3.16+ (5.2.3 train) and VCO 6.4.2.8+ (6.4.2 train). Other supported trains: fixes “coming” and will be listed when ready; Arista has not published a 6.1 or 7.0 patch build. VeloCloud Gateway and Edge appliances themselves are listed as not affected products for this CVE; EOS switches, CloudVision, and the rest of the Arista portfolio are out of scope for this advisory.

Exploitation status: Arista says the issue “was discovered externally and is known to be actively exploited.” It does not publish when attacks began or how widespread they are. Campaign size / victim count: Undisclosed. The Hacker News (Sep 22) notes the same and that THN contacted Arista for comment.

Until you can upgrade: restrict VCO web UI to trusted admin nets; monitor for known-malicious source IPs and unexpected outbound from the VCO host; consider blocking unused outbound ports; hunt backdoors/webshells; review unexpected admin changes. IoCs Arista flags if present (preserve state, call TAC): files /usr/local/sbin/.vcnode.js, /usr/local/sbin/vc-sysmond (MD5 dc78e206eaeadec59fc5801fe4556bd0), /etc/systemd/system/vc-sysmon.service; nginx header x-vc-opt; IPs 142.93.149.77 and 104.248.126.159. Post-upgrade IR may include credential rotation, admin-activity review, Edge-state validation, and restore/replace from trusted sources.

POV: After July’s separate VCO ITW (CVE-2026-16812), this is another control-plane max-severity on the same product line — this time gated on cert-based Edge auth, not default-open. Patch 5.2 / 6.4 now. If you are on 6.1 or 7.0 without a listed fix, open TAC and harden the web UI until the build lands. Sources: Arista SA-0183 Sep 22 + The Hacker News Sep 22.

Sources