Mastodon Mastodon Mastodon Mastodon

Critical CVE-2026-93952 vulnerability in VeloCloud Orchestrator is being actively exploited — patches are not available for all versions

Photo of author

CyberSecureFox Editorial Team

Published:

On 22 September 2026, Arista published Security Advisory 0183 describing the critical vulnerability CVE-2026-93952 in VeloCloud Orchestrator On-Prem — the server component that manages Edge devices in an SD-WAN infrastructure. The vulnerability received the maximum score of CVSS 3.1 — 10.0 (CVSS 4.0 — 9.5) and, according to Arista, is already being actively exploited by attackers. The issue affects deployments with certificate-based authentication of Edge devices, and as of publication fixes are available only for two of the four affected branches. Organizations using VeloCloud SD-WAN must immediately determine their configuration and take action.

Nature of the vulnerability and affected versions

The vulnerability is classified as CWE-20: Improper Input Validation. A remote attacker without operator or tenant credentials can gain access to privileged internal functions and compromise the VCO host. Successful exploitation jeopardizes the confidentiality, integrity, and availability of the orchestrator and all data it manages, and may also open up access for the attacker to connected Edge devices.

Affected versions of VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom):

  • 5.2.x branch — versions 5.2.3.15 and below
  • 6.1.x branch — versions 6.1.3.7 and below
  • 6.4.x branch — versions 6.4.2.7 and below
  • 7.0.x branch — versions 7.0.0.2 and below

Cloud and dedicated (Hosted/Dedicated) VCO instances were also affected; however, Arista reports that they have already been fixed.

It is worth noting that the statement about active exploitation comes solely from Arista — no independent confirmation from CISA, NVD or other organizations had been found at the time of publication. Arista does not disclose the start date of the attacks, their scale, or attribution.

Exploitation conditions: who is actually vulnerable

The vulnerability does not affect all VCO deployments. According to the advisory, three conditions must be met simultaneously for exploitation:

  1. Certificate-based authentication of Edge devices to the orchestrator must be configured.
  2. The attacker needs access to the public portion of the authentication certificate of an Edge device.
  3. Network access to the VCO web interface is required.

Operator or tenant credentials are not required.

Arista’s documentation on configuring Edge devices describes three authentication modes: Certificate Deactivated (a pre-shared key — PSK — is used), Certificate Acquire (a certificate is issued when the Edge is activated and updated automatically), and Certificate Required (a strict mode allowing only certificate-based authentication). Thus, the practical scope of the vulnerability is narrower than “all VCO deployments”: installations in Certificate Acquire and Certificate Required modes are at risk, whereas configurations with Certificate Deactivated (PSK) do not meet the exploitation conditions.

This is a significant difference from the July vulnerability in VeloCloud Orchestrator that we have already analyzed: that one affected VCO by default regardless of configuration.

Patches and uneven coverage

As of 22 September, Arista has released fixes only for two branches:

  • VCO 5.2.3.16 and above — for the 5.2.3 branch
  • VCO 6.4.2.8 and above — for the 6.4.2 branch

For branches 6.1.x and 7.0.x there are no fixes yet. Arista states that patches for supported branches will be added later. Organizations on these branches are in the most vulnerable position: the vulnerability is confirmed, it is being exploited, and the only options are compensating controls or contacting Arista TAC for individual upgrade recommendations. Customers on unsupported branches should also contact TAC.

Indicators of compromise

Arista emphasizes that no single indicator is conclusive proof of compromise via this vulnerability. A correlation-based approach is recommended — correlating several signs at once. The listed indicators are:

Files on the VCO host:

  • /usr/local/sbin/.vcnode.js
  • /usr/local/sbin/vc-sysmond (MD5: dc78e206eaeadec59fc5801fe4556bd0)
  • /etc/systemd/system/vc-sysmon.service

Network indicators:

  • HTTP header x-vc-opt in nginx logs
  • IP addresses: 142.93.149[.]77, 104.248.126[.]159

You should also check VCO web access logs for requests with unusual URL-like paths, encoded characters, calls to local or internal services, and abnormally high request rates.

Response recommendations

Until a fixed version is installed, Arista recommends the following compensating measures:

  • Restrict access to the VCO web interface to trusted administrative networks.
  • Monitor connections to the VCO from known malicious IP addresses.
  • Track unexpected outbound network traffic from the VCO host.
  • Consider blocking outbound ports that are not required for normal operation.
  • Check for the presence of backdoors and web shells.
  • Review recent administrator activity for unexpected changes.

After updating, Arista recommends carrying out full incident response: rotating credentials, reviewing administrator activity, validating the state of managed Edge devices and, if necessary, restoring or replacing the orchestrator from trusted sources. If signs of compromise are detected, preserve web access logs, application logs, system and database logs, as well as filesystem timestamps before making any changes.

For organizations that have previously encountered issues with Arista patches, the current situation requires special attention: two critical VCO vulnerabilities with active exploitation in three months form a steady trend. Action priorities: determine the authentication mode of Edge devices, check whether the VCO web interface is accessible from untrusted networks, install available patches (5.2.3.16 or 6.4.2.8), and for the 6.1.x and 7.0.x branches immediately implement compensating measures and contact Arista TAC.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.