thehackernews.com
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Arista Networks disclosed that attackers are actively exploiting a newly identified vulnerability in the on‑premises VeloCloud Orchestrator (VCO), the management server for Arista’s SD‑WAN Edge devices. The flaw, catalogued as CVE‑2026‑93952, receives a CVSS 3.1 rating of 10.0 and permits unauthenticated remote users to invoke privileged internal functions on VCO hosts that use certificate‑based authentication for Edge devices. Only orchestrators configured for certificate acquisition or required modes are vulnerable, and exploitation requires network access to the VCO web [...]