Critical Flaw in Arista VeloCloud Orchestrator Is Being Actively Exploited
A maximum-severity vulnerability in Arista's VeloCloud Orchestrator (VCO) — the management server behind VeloCloud SD-WAN deployments — is currently being exploited in the wild, according to an advisory Arista published on September 22.
What happened
Tracked as CVE-2026-93952 and rated 10.0 on the CVSS 3.1 scale, the flaw allows a remote, unauthenticated attacker to escalate privileges on the orchestrator itself. Exposure is limited to deployments where Edge devices authenticate to the orchestrator using certificates rather than a pre-shared key — one of three supported authentication modes.
Arista has not disclosed how the vulnerability was found beyond noting it was reported externally, nor has it shared when active exploitation began or how many organizations have been affected.
This is the second VeloCloud Orchestrator flaw to surface in a matter of months: a separate issue (CVE-2026-16812), which affected VCO regardless of configuration, was disclosed as exploited back in July. Some of the releases that patched that earlier bug remain vulnerable to this new one.
Patches are available now for the 5.2.x and 6.4.x release trains; fixes for 6.1.x and 7.0.x are still in progress. Organizations running unsupported release trains should contact Arista's support team about upgrade paths.
Why it matters
A successful attack can hand an intruder control of the orchestrator and the SD-WAN configuration data it holds — and from there, a path into every Edge device the orchestrator manages. For organizations running VeloCloud SD-WAN at scale, that turns a single management-plane compromise into a potential foothold across an entire branch network.
Because exposure hinges on how certificate authentication is configured rather than a single toggle, teams need to confirm their own deployment mode rather than assume they're unaffected.
What to do
- Patch immediately if you're on the 5.2.x or 6.4.x trains; track Arista's advisory for 6.1.x/7.0.x fixes.
- Restrict access to the VCO web interface to trusted administrative networks only.
- Monitor outbound traffic from the orchestrator host and consider blocking non-essential outbound ports.
- Hunt for compromise indicators, including unexpected files at
/usr/local/sbin/.vcnode.jsand/usr/local/sbin/vc-sysmond, a suspiciousvc-sysmon.servicesystemd unit, thex-vc-optHTTP header in nginx logs, and outbound connections to142.93.149[.]77or104.248.126[.]159. - Preserve evidence — web access, application, system, and database logs plus filesystem timestamps — before remediating if you suspect compromise.
- After patching, rotate credentials, review administrator activity, and consider restoring the orchestrator from a trusted source if compromise is suspected.
Need help assessing exposure or validating your SD-WAN management plane? 4tify's vulnerability assessment pipeline can help you confirm whether your deployment is affected and prioritize remediation.
