Find notable cyber news and cases, enriched with sources, timelines, and signals.

Arista mitigation guidance for Arista VeloCloud Orchestrator compensating controls for CVE-2026-93952

Advisory/Mitigation
First reported
Last updated
Happening score
H score 53
1 unique sources, 1 articles

Summary

Hide ▲

Arista issued temporary mitigation steps for exposed VeloCloud Orchestrator (VCO) deployments while a fixed release is pending, limiting the risk from actively exploited CVE-2026-93952. The guidance applies to on-premises VCO systems that use certificate-based authentication and can be reached through the VCO web interface. Administrators are told to restrict access, monitor for malicious activity, and look for backdoor daemons or webshells on the host. The response also includes preserving logs and rotating credentials after remediation where practical.

Related Happenings

Arista security patch release for CVE-2026-93952

Security Patch Release
H score53 First: 22.09.2026 15:29 Last: 22.09.2026 15:29 Sources 1

How related: As of September 22, fixed releases are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains.

About this happening: Arista released fixed VeloCloud Orchestrator (VCO) builds for the 5.2 and 6.4 trains, reducing exposure for deployments tied to CVE-2026-93952. The patch set cover...

VeloCloud Orchestrator certificate-based privilege escalation (CVE-2026-93952)

Vulnerability
H score49 First: 22.09.2026 15:29 Last: 22.09.2026 15:29 Sources 1

How related: Arista said the flaw "was discovered externally and is known to be actively exploited."

About this happening: CVE-2026-93952 is an actively exploited flaw in VeloCloud Orchestrator (VCO) that can let a remote attacker with no login access privilege internal functions and compr...

Cisco ISE and ISE-PIC actively exploited authentication bypass (CVE-2026-76460)

Vulnerability
H score51 First: 17.09.2026 10:20 Last: 17.09.2026 10:20 Sources 1

About this happening: Cisco ISE and ISE-PIC are facing CVE-2026-76460, a maximum-severity API authentication bypass that is actively exploited in the wild. The flaw can let remote attac...

Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog ordered federal agencies to patch systems against CVE-2026-76460 for within

Public Sector Action
H score37 First: 17.09.2026 10:20 Last: 17.09.2026 10:20 Sources 1

About this happening: CISA ordered federal agencies to patch CVE-2026-76460 within three days, imposing an urgent remediation deadline for an actively exploited Cisco flaw. The orde...

CISA mitigation guidance for CISA Adds Cisco Secure FMC CVE-2026-20079 to KEV Sets Sept. 12 Deadline

Advisory/Mitigation
H score58 First: 10.09.2026 00:40 Last: 10.09.2026 00:40 Sources 1

About this happening: CISA added CVE-2026-20079 to the KEV catalog and ordered Federal Civilian Executive Branch (FCEB) agencies to patch affected Cisco Secure FMC systems by Sept...

Timeline

  1. 22.09.2026 15:29 2 articles · 3h ago

    Arista issues temporary mitigation steps for exposed VeloCloud Orchestrator deployments

    Mitigation Patch Update

    Arista said on September 22 that CVE-2026-93952 is actively exploited against on-premises VeloCloud Orchestrator deployments using certificate-based authentication and that fixed releases were still pending for some release trains. Until a fixed release is installed, the guidance tells administrators to limit access to the VCO web interface to trusted administrative networks, monitor for access from known malicious IP addresses and unexpected outbound traffic, consider blocking unnecessary outbound ports, watch for backdoor daemons and webshells, review recent administrator activity, preserve logs and system state if compromise is suspected, and rotate credentials after remediation.

    Show sources