New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
AI-summarised brief · reviewed before publication
Arista Networks disclosed that attackers are actively exploiting a newly identified vulnerability in the on‑premises VeloCloud Orchestrator (VCO), the management server for Arista’s SD‑WAN Edge devices. The flaw, catalogued as CVE‑2026‑93952, receives a CVSS 3.1 rating of 10.0 and permits unauthenticated remote users to invoke privileged internal functions on VCO hosts that use certificate‑based authentication for Edge devices. Only orchestrators configured for certificate acquisition or required modes are vulnerable, and exploitation requires network access to the VCO web interface and the public portion of an Edge certificate. Fixed releases are available for the 5.2 and 6.4 release trains; patches for 6.1 and 7.0 are pending. Arista has patched dedicated VCO instances and advises customers to upgrade, monitor logs for anomalous requests.
💡 Why It Matters
- · A breach of the VCO gives attackers command over every Edge device in an SD‑WAN, effectively opening a backdoor to an organization’s entire wide‑area network.