CVE-2026-93952
Summary
A pre-authentication flaw in on-premises VeloCloud Orchestrator (VCO) that may allow a remote attacker to reach privileged internal functionality and affect the orchestrator host, scored CVSS 3.1 10.0.
Details
NVD records CVE-2026-93952 at CVSS 3.1 10.0 (Critical) — vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H — with the CVSS 4.0 base score at 9.5. Arista's description states that successful exploitation "may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator", and that hosted and dedicated instances of VCO were already patched by the vendor.
Exposure is conditional: an orchestrator is affected where certificate-based authentication from VeloCloud Edge to VCO is configured, and the attacker also needs network access to the VCO web interface plus the public part of an Edge's authentication certificate. Certificate Deactivated deployments, which authenticate Edges by pre-shared key, do not meet the condition.
Exploitation and defensive guidance
Arista states the flaw "was discovered externally and is known to be actively exploited". As of 22 September fix versions were available for the 5.2 train (5.2.3.16 and later) and the 6.4 train (6.4.2.8 and later); no fix existed for the 6.1 and 7.0 trains, and customers on an unsupported train were directed to Arista's Technical Assistance Center. CISA added it to the KEV catalog on 22 September 2026.
Australian Significance
VCO is the orchestration plane for an SD-WAN estate, so a compromise there reaches the Edge devices it manages — an edge-perimeter exposure of the kind that matters to Australian APRA CPS 234-regulated entities running SD-WAN across branches, and to critical-infrastructure operators whose network segmentation depends on the orchestrator's policy. CVE-2026-16812, a CVSS 10.0 command injection in the same product, was reported exploited in July 2026, so this is the second VCO zero-day of the year and patch assurance should cover the whole orchestrator/Edge trust relationship rather than the appliance alone.
Related Pages
Sources: raw/digests/Cyber-Digest-2026-09-23.md