CVE-2026-93952
Published Sep 22, 2026
Last updated an hour ago
- Description
- VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.
- Source
- psirt@arista.com
- NVD status
- Analyzed
- Products
- velocloud_orchestrator
CVSS 4.0
- Type
- Secondary
- Base score
- 9.5
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Exploit added on
- Sep 22, 2026
- Exploit action due
- Sep 25, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- psirt@arista.com
- CWE-20
- Hype score
- Not currently trending
Arista VeloCloud Orchestrator Flaw CVE-2026-93952 Allows Remote Compromise CVE-2026-93952 is a CVSS 10.0 input validation flaw in Arista VeloCloud Orchestrator on-prem allowing unauthenticated remote… Full write-up → link in bio #cybersecurity #infosec #cve #kev #arista htt
@HotaSamit
23 Sept 2026
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
F5 BIG-IP APM, Check Point Security Gateway und VeloCloud Orchestrator stehen wegen aktiv ausgenutzter Sicherheitslücken im Fokus. Ein Überblick über CVE-2026-94127, CVE-2026-85102, CVE-2026-93616 und CVE-2026-93952. https://t.co/UIVtmEjfy1
@oliverjessner
23 Sept 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。Check Point複数製品のCVE-2026-85102+CVE-2026-93616、Arista VeloCloud OrchestratorのCVE-2026-93952、F5 BIG-IP APMのCVE-20
@__kokumoto
23 Sept 2026
679 Impressions
0 Retweets
1 Like
1 Bookmark
1 Reply
0 Quotes
Arista warns of active exploitation of CVE-2026-93952, CVSS 10.0 RCE in on-prem VeloCloud Orchestrator with cert-auth enabled. Isolate and patch immediately. #VeloCloud #InfoSec #CVE https://t.co/6hwPbKkbqz
@CyberWorldOps
22 Sept 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ VeloCloud Orchestrator : Arista confirme l’exploitation active de CVE-2026-93952 (CVSS 10). Les VCO on-prem avec auth Edge par certificat sont exposés ; correctifs 5.2.3.16 et 6.4.2.8 disponibles, 6.1/7.0 sans patch. Isolez/patch. #Cyber #CVE
@TwitGri
22 Sept 2026
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E90ACBD1-E408-4DD5-B8DC-D3E021FC7E7A",
"versionEndExcluding": "5.2.3.16",
"versionStartIncluding": "5.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*",
"matchCriteriaId": "86BE5508-B49D-42FC-82E7-FCA23806DF8D",
"versionEndIncluding": "6.1.3.7",
"versionStartIncluding": "6.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*",
"matchCriteriaId": "9592E38C-B71C-499C-9B7E-317E8E20794C",
"versionEndExcluding": "6.4.2.8",
"versionStartIncluding": "6.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*",
"matchCriteriaId": "633BE61D-90FD-4868-9459-D4DB1B2CF653",
"versionEndIncluding": "7.0.0.2",
"versionStartIncluding": "7.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]