Arista mitigation guidance for Arista VeloCloud Orchestrator compensating controls for CVE-2026-93952
Advisory/Mitigation
Summary
Hide ▲
Show ▼
Arista issued temporary mitigation steps for exposed VeloCloud Orchestrator (VCO) deployments while a fixed release is pending, limiting the risk from actively exploited CVE-2026-93952. The guidance applies to on-premises VCO systems that use certificate-based authentication and can be reached through the VCO web interface. Administrators are told to restrict access, monitor for malicious activity, and look for backdoor daemons or webshells on the host. The response also includes preserving logs and rotating credentials after remediation where practical.
Related Happenings
Arista security patch release for CVE-2026-93952
Security Patch Release
H score53
First: 22.09.2026 15:29
Last: 22.09.2026 15:29
Sources 1
How related:
As of September 22, fixed releases are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains.
About this happening:
Arista released fixed VeloCloud Orchestrator (VCO) builds for the 5.2 and 6.4 trains, reducing exposure for deployments tied to CVE-2026-93952. The patch set cover...
Arista security patch release for CVE-2026-93952
Security Patch ReleaseHow related: As of September 22, fixed releases are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains.
About this happening: Arista released fixed VeloCloud Orchestrator (VCO) builds for the 5.2 and 6.4 trains, reducing exposure for deployments tied to CVE-2026-93952. The patch set cover...
VeloCloud Orchestrator certificate-based privilege escalation (CVE-2026-93952)
Vulnerability
H score49
First: 22.09.2026 15:29
Last: 22.09.2026 15:29
Sources 1
How related:
Arista said the flaw "was discovered externally and is known to be actively exploited."
About this happening:
CVE-2026-93952 is an actively exploited flaw in VeloCloud Orchestrator (VCO) that can let a remote attacker with no login access privilege internal functions and compr...
VeloCloud Orchestrator certificate-based privilege escalation (CVE-2026-93952)
VulnerabilityHow related: Arista said the flaw "was discovered externally and is known to be actively exploited."
About this happening: CVE-2026-93952 is an actively exploited flaw in VeloCloud Orchestrator (VCO) that can let a remote attacker with no login access privilege internal functions and compr...
Cisco ISE and ISE-PIC actively exploited authentication bypass (CVE-2026-76460)
Vulnerability
H score51
First: 17.09.2026 10:20
Last: 17.09.2026 10:20
Sources 1
About this happening:
Cisco ISE and ISE-PIC are facing CVE-2026-76460, a maximum-severity API authentication bypass that is actively exploited in the wild. The flaw can let remote attac...
Cisco ISE and ISE-PIC actively exploited authentication bypass (CVE-2026-76460)
VulnerabilityAbout this happening: Cisco ISE and ISE-PIC are facing CVE-2026-76460, a maximum-severity API authentication bypass that is actively exploited in the wild. The flaw can let remote attac...
Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog ordered federal agencies to patch systems against CVE-2026-76460 for within
Public Sector Action
H score37
First: 17.09.2026 10:20
Last: 17.09.2026 10:20
Sources 1
About this happening:
CISA ordered federal agencies to patch CVE-2026-76460 within three days, imposing an urgent remediation deadline for an actively exploited Cisco flaw. The orde...
Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog ordered federal agencies to patch systems against CVE-2026-76460 for within
Public Sector ActionAbout this happening: CISA ordered federal agencies to patch CVE-2026-76460 within three days, imposing an urgent remediation deadline for an actively exploited Cisco flaw. The orde...
CISA mitigation guidance for CISA Adds Cisco Secure FMC CVE-2026-20079 to KEV Sets Sept. 12 Deadline
Advisory/Mitigation
H score58
First: 10.09.2026 00:40
Last: 10.09.2026 00:40
Sources 1
About this happening:
CISA added CVE-2026-20079 to the KEV catalog and ordered Federal Civilian Executive Branch (FCEB) agencies to patch affected Cisco Secure FMC systems by Sept...
CISA mitigation guidance for CISA Adds Cisco Secure FMC CVE-2026-20079 to KEV Sets Sept. 12 Deadline
Advisory/MitigationAbout this happening: CISA added CVE-2026-20079 to the KEV catalog and ordered Federal Civilian Executive Branch (FCEB) agencies to patch affected Cisco Secure FMC systems by Sept...
Timeline
-
22.09.2026 15:29 2 articles · 3h ago
Arista issues temporary mitigation steps for exposed VeloCloud Orchestrator deployments
Mitigation Patch UpdateArista said on September 22 that CVE-2026-93952 is actively exploited against on-premises VeloCloud Orchestrator deployments using certificate-based authentication and that fixed releases were still pending for some release trains. Until a fixed release is installed, the guidance tells administrators to limit access to the VCO web interface to trusted administrative networks, monitor for access from known malicious IP addresses and unexpected outbound traffic, consider blocking unnecessary outbound ports, watch for backdoor daemons and webshells, review recent administrator activity, preserve logs and system state if compromise is suspected, and rotate credentials after remediation.
Show sources
- New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups — thehackernews.com — 22.09.2026 15:29
- New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups — thehackernews.com — 22.09.2026 15:29