Arista VeloCloud Orchestrator CVE-2026-93952 (CVSS 10.0) unauth privilege on cert-auth on-prem VCO — actively exploited
Arista Security Advisory 0183 (CVE published 22 September 2026) documents CVE-2026-93952 in on-premises VeloCloud Orchestrator (VCO): a remote attacker with network access to the VCO web interface and the public part of an Edge authentication certificate may reach privileged internal functionality and impact the VCO host when certificate-based Edge→VCO authentication is configured. Arista/CNA CVSS 3.1 10.0 Critical (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) and CVSS 4.0 9.5; Arista states the issue was discovered externally and is known to be actively exploited. Hosted/Dedicated VCO already patched. On-prem trains: 5.2.3.15 and earlier → fix 5.2.3.16+; 6.4.2.7 and earlier → fix 6.4.2.8+; 6.1.3.7 and earlier and 7.0.0.2 and earlier — no fix listed as of 22 Sep 2026 (Arista says supported-train fixes forthcoming). Distinct from July exploited VCO CVE-2026-16812. Primary: Arista SA-0183 URL; metadata: CVE.report; wire: The Hacker News 22 Sep 2026.
- Product
- Arista VeloCloud Orchestrator (VCO) on-prem; Hosted/Dedicated already patched
- Versions
- On-prem affected (cert-based Edge auth): 5.2.0–5.2.3.15 (fix ≥5.2.3.16); 6.1.0–6.1.3.7 (no fix yet per 22 Sep coverage); 6.4.0–6.4.2.7 (fix ≥6.4.2.8); 7.0.0–7.0.0.2 (no fix yet). Hosted/Dedicated: patched by Arista.
- CVSS
- (CVSS 3.1 Critical; Arista/CNA) / 9.5 (CVSS 4.0 Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Upgrade on-prem VCO to fixed builds where available (5.2.3.16+, 6.4.2.8+); restrict VCO web exposure; confirm Hosted/Dedicated status with Arista; review VCO web logs for unusual URL-like paths/encoded characters/high rates; rotate credentials and review managed Edges if compromise suspected; watch SA-0183 for 6.1/7.0 fixes
Primary: Arista Security Advisory 0183 — VeloCloud Orchestrator CVE-2026-93952 · Vendor: Arista — Security Advisory 0183 · CVE: CVE-2026-93952, CVE-2026-16812 · CVE.report — CVE-2026-93952; also The Hacker News 22 Sep 2026
