Tech News
← Home  ·  All topics

Velocloud Orchestrator

1 GoKawiil brief on this topic

Arista fixes actively exploited VeloCloud Orchestrator zero-day, CISA sets Sept 25 deadline

Arista Networks has issued patches for CVE-2026-93952, a maximum-severity flaw in on-premises deployments of VeloCloud Orchestrator, the centralized management platform for VeloCloud SD-WANs. The bug, an improper input validation issue affecting setups using certificate-based authentication between edge devices and the orchestrator, lets remote attackers gain privileged internal access without credentials or user interaction, and Arista says it is already being exploited in the wild.