Arista fixes actively exploited VeloCloud Orchestrator zero-day, CISA sets Sept 25 deadline
Arista Networks has issued patches for CVE-2026-93952, a maximum-severity flaw in on-premises deployments of VeloCloud Orchestrator, the centralized management platform for VeloCloud SD-WANs. The bug, an improper input validation issue affecting setups using certificate-based authentication between edge devices and the orchestrator, lets remote attackers gain privileged internal access without credentials or user interaction, and Arista says it is already being exploited in the wild.
GoKawiil's interpretation of the reporting above, not reported fact.
CISA's addition of the flaw to its Known Exploited Vulnerabilities catalog, with a September 25 remediation deadline for federal agencies, signals that exploitation is considered urgent and widespread enough to warrant mandatory action. Because SD-WAN orchestrators sit at the center of enterprise network management, compromise could let attackers pivot into connected edge devices across an organization's infrastructure, making prompt patching and interim mitigations like restricting web interface access especially important.
- CVE-2026-93952 is a maximum-severity, actively exploited zero-day in VeloCloud Orchestrator On-Prem deployments.
- Arista has patched hosted VCO versions 5.2.3.16+ and 6.4.2.8+, with fixes for older versions still pending.
- CISA has mandated federal agencies secure affected systems by September 25, underscoring the flaw's urgency.
Source: bleepingcomputer.com, 2026-09-23
Published there as: “Arista patches actively exploited VeloCloud Orchestrator zero-day”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.