CVE-2026-93952

Published Sep 22, 2026

Last updated an hour ago

Exploit knownCVSS critical 9.5
Zero-day
IoT
Supply chain

Overview

Description
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.
Source
psirt@arista.com
NVD status
Analyzed
Products
velocloud_orchestrator

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.5
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
Exploit added on
Sep 22, 2026
Exploit action due
Sep 25, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

psirt@arista.com
CWE-20

Social media

Hype score
Not currently trending
  1. Arista VeloCloud Orchestrator Flaw CVE-2026-93952 Allows Remote Compromise CVE-2026-93952 is a CVSS 10.0 input validation flaw in Arista VeloCloud Orchestrator on-prem allowing unauthenticated remote… Full write-up → link in bio #cybersecurity #infosec #cve #kev #arista htt

    @HotaSamit

    23 Sept 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. F5 BIG-IP APM, Check Point Security Gateway und VeloCloud Orchestrator stehen wegen aktiv ausgenutzter Sicherheitslücken im Fokus. Ein Überblick über CVE-2026-94127, CVE-2026-85102, CVE-2026-93616 und CVE-2026-93952. https://t.co/UIVtmEjfy1

    @oliverjessner

    23 Sept 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。Check Point複数製品のCVE-2026-85102+CVE-2026-93616、Arista VeloCloud OrchestratorのCVE-2026-93952、F5 BIG-IP APMのCVE-20

    @__kokumoto

    23 Sept 2026

    679 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  4. Arista warns of active exploitation of CVE-2026-93952, CVSS 10.0 RCE in on-prem VeloCloud Orchestrator with cert-auth enabled. Isolate and patch immediately. #VeloCloud #InfoSec #CVE https://t.co/6hwPbKkbqz

    @CyberWorldOps

    22 Sept 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ⚠️ VeloCloud Orchestrator : Arista confirme l’exploitation active de CVE-2026-93952 (CVSS 10). Les VCO on-prem avec auth Edge par certificat sont exposés ; correctifs 5.2.3.16 et 6.4.2.8 disponibles, 6.1/7.0 sans patch. Isolez/patch. #Cyber #CVE

    @TwitGri

    22 Sept 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations