Arista Urges Immediate Patching of Exploited VCO Zero-Day
A critical zero-day vulnerability (CVE-2026-93952) in Arista VeloCloud Orchestrator (VCO) on-premises deployments allows remote attackers to access privileged internal functionality via improper input validation. The flaw affects VCO versions prior to 5.2.3.16 and 6.4.2.8 and requires network access to the VCO web interface and access to the public portion of the VeloCloud Edge authentication certificate. No tenant or operator credentials are needed. Arista has released patches and urges immediate updating. The vulnerability is actively exploited and impacts confidentiality, integrity, and availability of the orchestrator and its managed data.
AI Analysis
Technical Summary
The vulnerability CVE-2026-93952 is an improper input validation flaw in Arista VeloCloud Orchestrator (VCO) on-premises versions prior to 5.2.3.16 and 6.4.2.8. It allows remote attackers with network access to the VCO web interface and access to the public portion of the VeloCloud Edge authentication certificate to bypass authentication and access privileged internal functions without tenant or operator credentials. This zero-day has been actively exploited in the wild. The flaw affects only on-premises VCO deployments where certificate-based authentication from VeloCloud Edge to VCO is configured. Arista has released urgent patches for affected versions and recommends immediate application. The vulnerability was added to CISA’s Known Exploited Vulnerabilities list, with federal agencies required to patch within three days.
Potential Impact
Successful exploitation allows remote attackers to access privileged internal functionality of the VeloCloud Orchestrator, potentially compromising the confidentiality, integrity, and availability of the orchestrator and the data it manages. The flaw does not require valid tenant or operator credentials but does require network access to the VCO web interface and access to the public portion of the VeloCloud Edge authentication certificate. Deployments that restrict access to the VCO web interface have a reduced risk of exposure.
Mitigation Recommendations
Arista has released official patches resolving this vulnerability in VCO versions 5.2.3.16 and 6.4.2.8 for the 5.2.x and 6.1.x release trains, respectively, with additional patches forthcoming for other trains. Immediate application of these patches is strongly recommended. Organizations should limit network access to the VCO web interface to reduce exposure risk. Arista advises reviewing VCO web access logs, backend application logs, and system logs for suspicious activity as no definitive indicators of compromise are currently known.
Arista Urges Immediate Patching of Exploited VCO Zero-Day
Description
A critical zero-day vulnerability (CVE-2026-93952) in Arista VeloCloud Orchestrator (VCO) on-premises deployments allows remote attackers to access privileged internal functionality via improper input validation. The flaw affects VCO versions prior to 5.2.3.16 and 6.4.2.8 and requires network access to the VCO web interface and access to the public portion of the VeloCloud Edge authentication certificate. No tenant or operator credentials are needed. Arista has released patches and urges immediate updating. The vulnerability is actively exploited and impacts confidentiality, integrity, and availability of the orchestrator and its managed data.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-93952 is an improper input validation flaw in Arista VeloCloud Orchestrator (VCO) on-premises versions prior to 5.2.3.16 and 6.4.2.8. It allows remote attackers with network access to the VCO web interface and access to the public portion of the VeloCloud Edge authentication certificate to bypass authentication and access privileged internal functions without tenant or operator credentials. This zero-day has been actively exploited in the wild. The flaw affects only on-premises VCO deployments where certificate-based authentication from VeloCloud Edge to VCO is configured. Arista has released urgent patches for affected versions and recommends immediate application. The vulnerability was added to CISA’s Known Exploited Vulnerabilities list, with federal agencies required to patch within three days.
Potential Impact
Successful exploitation allows remote attackers to access privileged internal functionality of the VeloCloud Orchestrator, potentially compromising the confidentiality, integrity, and availability of the orchestrator and the data it manages. The flaw does not require valid tenant or operator credentials but does require network access to the VCO web interface and access to the public portion of the VeloCloud Edge authentication certificate. Deployments that restrict access to the VCO web interface have a reduced risk of exposure.
Mitigation Recommendations
Arista has released official patches resolving this vulnerability in VCO versions 5.2.3.16 and 6.4.2.8 for the 5.2.x and 6.1.x release trains, respectively, with additional patches forthcoming for other trains. Immediate application of these patches is strongly recommended. Organizations should limit network access to the VCO web interface to reduce exposure risk. Arista advises reviewing VCO web access logs, backend application logs, and system logs for suspicious activity as no definitive indicators of compromise are currently known.
Technical Details
- Classification
- {"confidence":0.75,"severitySource":"stated","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/arista-urges-immediate-patching-of-exploited-vco-zero-day/","fetched":true,"fetchedAt":"2026-09-23T08:47:47.111Z","wordCount":941}
Threat ID: 6ab39233f7a7c54106874519
Added to database: 09/23/2026, 08:47:47 UTC
Last enriched: 09/23/2026, 08:47:53 UTC
Last updated: 09/23/2026, 09:17:19 UTC
Views: 20
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.