LATEST View all updates

CVE-2026-93952: VeloCloud Orchestrator Actively Exploited — Affected Versions and Fixes

Arista confirms active use of CVE-2026-93952; on-prem VCO customers must check configuration, versions and fixes.

VeloCloud Orchestrator security illustration showing on-prem management-plane exposure and remediation

Signal Brief

  • Arista confirms active exploitation of CVE-2026-93952, but exposure depends on the documented on-prem VCO configuration and network reachability.
  • Affected 5.2 deployments have a fix at 5.2.3.16 or later, and affected 6.4 deployments have a fix at 6.4.2.8 or later.
  • The reviewed advisory does not yet list fixed releases for affected 6.1 and 7.0 trains; those operators need exposure reduction, monitoring and current Arista guidance.
  • If compromise is suspected, patching alone is not enough; Arista recommends broader incident-response and managed-device validation.

CVE-2026-93952 is an actively exploited vulnerability in VeloCloud Orchestrator that Arista rates CVSS 10.0 under CVSS v3.1. The current risk is not identical for every VeloCloud deployment: Arista says Hosted and Dedicated VCO environments have already been patched, while affected on-prem customers must check their authentication configuration, exact release train and available remediation.

For the documented exposure, Arista says an attacker needs network access to the VCO web interface, access to the public portion of a VeloCloud Edge authentication certificate, and an environment using certificate-based Edge-to-Orchestrator authentication. VCO tenant or operator credentials are not required. Because active exploitation is confirmed, operators should assess both patch status and whether compromise may already have occurred.

CVE-2026-93952 affected versions and fixes

VCO on-prem train Affected releases Fixed release currently listed Current action
5.2 5.2.0 through 5.2.3.15 5.2.3.16 or later in the 5.2.3 train Upgrade to a fixed build
6.1 6.1.0 through 6.1.3.7 No fixed 6.1 release listed in the reviewed advisory Reduce exposure, monitor and follow current Arista/TAC guidance
6.4 6.4.0 through 6.4.2.7 6.4.2.8 or later in the 6.4.2 train Upgrade to a fixed build
7.0 7.0.0 through 7.0.0.2 No fixed 7.0 release listed in the reviewed advisory Reduce exposure, monitor and follow current Arista/TAC guidance

Arista says fixes for other supported affected release trains will be added as they become available. Administrators should not invent or assume a target version for the 6.1 or 7.0 trains before the vendor publishes one.

VeloCloud Orchestrator CVE-2026-93952 affected and fixed version matrix with exposure checks
Infographic showing the VCO deployment check, affected release ranges, available fixes and pending 6.1 and 7.0 remediation state.

Which deployments meet the documented exposure conditions?

Version alone is not the complete exposure test. Arista identifies certificate-based authentication between VeloCloud Edge devices and the Orchestrator as a required condition. The attacker also needs access to the public portion of an Edge authentication certificate and network reachability to the VCO web interface.

That distinction matters because the advisory does not support saying every on-prem VCO is exploitable under every configuration. It also does not support saying the attacker needs normal VCO tenant or operator credentials.

Hosted and Dedicated VCO environments are already patched

Arista says Hosted and Dedicated VeloCloud Orchestrator environments were affected but have already been patched. The urgent version-remediation decision therefore falls primarily on organizations operating their own on-prem VCO deployments.

Hosted or Dedicated customers should continue following current vendor guidance, but they should not be told to apply the same on-prem software update unless Arista specifically instructs them to do so.

Why active exploitation changes the response

Arista explicitly says CVE-2026-93952 is known to be actively exploited. Successful exploitation may compromise the confidentiality, integrity and availability of the Orchestrator host and the data it manages. Arista also warns that compromise of the VCO platform may allow access to managed VeloCloud Edge devices.

CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 22, with a September 25 remediation due date for covered U.S. federal civilian agencies. CERT-In separately issued guidance on September 23 listing the affected VCO on-prem version ranges.

What should on-prem VCO administrators do?

Identify the deployment type.

Confirm whether the VCO is Hosted, Dedicated or on-prem. Arista says Hosted and Dedicated environments have already been patched.

Check the exact VCO release.

Match the current version against the affected 5.2, 6.1, 6.4 and 7.0 ranges before deciding remediation.

Verify the authentication mode.

Determine whether certificate-based Edge-to-VCO authentication is configured, because Arista identifies it as a required condition for this issue.

Review management-interface exposure.

Check which networks can reach the VCO web interface. Arista recommends restricting administrative access to trusted networks as an exposure-reduction measure.

Apply a listed fixed build where available.

Upgrade affected 5.2 deployments to 5.2.3.16 or later in the supported train and affected 6.4 deployments to 6.4.2.8 or later.

Handle 6.1 and 7.0 carefully.

The reviewed advisory does not yet list fixed builds for these affected trains. Restrict exposure, monitor closely and use current Arista or TAC guidance for the supported remediation path.

Look for signs of compromise.

Monitor unexpected outbound network activity, unnecessary outbound ports, backdoor daemons or webshells, and recent administrator activity for unexpected changes.

Do not stop at patching if compromise is suspected.

Use incident-response procedures that may include credential rotation, administrator-activity review, validation of managed Edge devices and restoration or replacement of the Orchestrator from trusted sources.

There is no single definitive indicator of compromise

Arista says there is no single definitive IOC for this vulnerability. A clean result from one indicator therefore does not prove that an exposed VCO was never compromised. Operators should combine network monitoring, administrator-activity review, host inspection and managed-device validation according to their incident-response process.

The advisory specifically highlights unexpected outbound activity, unnecessary outbound listening or connection behavior, backdoor daemons or webshells and unusual administrator changes as areas to investigate.

What if the VCO may already have been compromised?

A software update closes the documented vulnerability path, but it does not by itself prove that a previously exposed host is trustworthy. Arista’s guidance includes reviewing administrator activity, rotating relevant credentials, validating the state of managed Edge devices and restoring or replacing affected Orchestrator instances from trusted sources where appropriate.

Organizations with evidence of compromise should therefore treat remediation as an incident-response problem as well as a patch-management problem.

What remains unknown?

The reviewed evidence does not establish the threat actor, the date exploitation began, the number or geography of compromised deployments, a definitive IOC or the prevalence of downstream Edge compromise. TPS also did not establish a confirmed public exploit-code state. Fixed builds for the affected 6.1 and 7.0 trains were not listed in the reviewed Arista advisory.

This article should be updated on the same URL when Arista publishes additional fixed releases, changes the affected-version matrix, releases new compromise indicators, adds incident-response guidance, or when CISA, CERT-In or other authoritative sources materially change the exploitation or remediation state.

Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

  2. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led article for informational and editorial guidance. Arista confirms active exploitation of CVE-2026-93952, but exposure is configuration-dependent and fixed-build availability differs by VeloCloud Orchestrator release train. TPS did not establish a definitive IOC, attacker attribution or fixed releases for every affected train. Verify the latest Arista, CISA and CERT-In guidance before consequential remediation or incident-response action.