Vulnerability
Published 2026-09-22
Verified 2026-09-27

Arista VeloCloud Orchestrator CVE-2026-93952 (CVSS 10.0) unauth privilege on cert-auth on-prem VCO — actively exploited

Arista Security Advisory 0183 (CVE published 22 September 2026) documents CVE-2026-93952 in on-premises VeloCloud Orchestrator (VCO): a remote attacker with network access to the VCO web interface and the public part of an Edge authentication certificate may reach privileged internal functionality and impact the VCO host when certificate-based Edge→VCO authentication is configured. Arista/CNA CVSS 3.1 10.0 Critical (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) and CVSS 4.0 9.5; Arista states the issue was discovered externally and is known to be actively exploited. Hosted/Dedicated VCO already patched. On-prem trains: 5.2.3.15 and earlier → fix 5.2.3.16+; 6.4.2.7 and earlier → fix 6.4.2.8+; 6.1.3.7 and earlier and 7.0.0.2 and earlier — no fix listed as of 22 Sep 2026 (Arista says supported-train fixes forthcoming). Distinct from July exploited VCO CVE-2026-16812. Primary: Arista SA-0183 URL; metadata: CVE.report; wire: The Hacker News 22 Sep 2026.

Product
Arista VeloCloud Orchestrator (VCO) on-prem; Hosted/Dedicated already patched
Versions
On-prem affected (cert-based Edge auth): 5.2.0–5.2.3.15 (fix ≥5.2.3.16); 6.1.0–6.1.3.7 (no fix yet per 22 Sep coverage); 6.4.0–6.4.2.7 (fix ≥6.4.2.8); 7.0.0–7.0.0.2 (no fix yet). Hosted/Dedicated: patched by Arista.
CVSS
(CVSS 3.1 Critical; Arista/CNA) / 9.5 (CVSS 4.0 Critical)
Exploited in Australia?
unknown
Patch to
Upgrade on-prem VCO to fixed builds where available (5.2.3.16+, 6.4.2.8+); restrict VCO web exposure; confirm Hosted/Dedicated status with Arista; review VCO web logs for unusual URL-like paths/encoded characters/high rates; rotate credentials and review managed Edges if compromise suspected; watch SA-0183 for 6.1/7.0 fixes

Primary: Arista Security Advisory 0183 — VeloCloud Orchestrator CVE-2026-93952 · Vendor: Arista — Security Advisory 0183 · CVE: CVE-2026-93952, CVE-2026-16812 · CVE.report — CVE-2026-93952; also The Hacker News 22 Sep 2026

vulnerabilities network cloud