Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-23 · updated: 2026-09-23 · tags: [incident, global] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: true

Arista disclosed CVE-2026-93952 in on-premises VeloCloud Orchestrator (VCO) — the server that manages the Edge devices in a VeloCloud SD-WAN — with a CVSS 3.1 score of 10.0, and said the flaw "was discovered externally and is known to be actively exploited". A remote attacker with no login access can use it to privilege internal functions and affect the VCO host; because the orchestrator holds the trust relationships and configuration for the Edges it manages, a compromise there reaches the managed estate as well. Only orchestrators configured to authenticate their Edges by certificate are exposed, and the attacker also needs network access to the VCO web interface plus the public part of an Edge's authentication certificate. Fixes were available on 22 September for the 5.2 (5.2.3.16 and later) and 6.4 (6.4.2.8 and later) trains, with no fix yet for 6.1 and 7.0 and hosted and dedicated instances already patched. The affected releases include versions that had been patched against a different VCO flaw, CVE-2026-16812, reported as exploited in July — the second time this year that VCO has been attacked through a vulnerability in the product itself rather than through customer misconfiguration. CISA added it to the KEV catalog the same day.

Attribute Detail
Sector Global (Macro)
Date 2026-09-23
Source The Hacker News
Reliability Tier 2
CVEs CVE-2026-16812, CVE-2026-93952