Find notable cyber news and cases, enriched with sources, timelines, and signals.

Arista security patch release for CVE-2026-93952

Security Patch Release
First reported
Last updated
Happening score
H score 53
1 unique sources, 1 articles

Summary

Hide ▲

Arista released fixed VeloCloud Orchestrator (VCO) builds for the 5.2 and 6.4 trains, reducing exposure for deployments tied to CVE-2026-93952. The patch set covers on-premises and Hosted/Dedicated VCO versions, while 6.1 and 7.0 were still awaiting fixes as of September 22. The release matters because VCO manages Edge devices in VeloCloud SD-WAN and compromise can extend beyond the orchestrator itself.

Related Happenings

Arista mitigation guidance for Arista VeloCloud Orchestrator compensating controls for CVE-2026-93952

Advisory/Mitigation
H score53 First: 22.09.2026 15:29 Last: 22.09.2026 15:29 Sources 1

How related: Until a fixed release is installed, Arista recommends these steps:

About this happening: Arista issued temporary mitigation steps for exposed VeloCloud Orchestrator (VCO) deployments while a fixed release is pending, limiting the risk from actively exploited...

GitLab CE/EE security update for CVE-2026-85706

Security Patch Release
H score44 First: 14.09.2026 10:06 Last: 14.09.2026 10:06 Sources 1

About this happening: GitLab released CE/EE fixes for CVE-2026-85706, and users were urged to patch immediately to close a repository commits API flaw that can expose credentials and se...

Gitea security patch release for CVE-2026-59774

Security Patch Release
H score65 First: 05.08.2026 14:04 Last: 05.08.2026 14:04 Sources 1

About this happening: Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...

Arista VeloCloud Orchestrator security update for CVE-2026-16812

Security Patch Release
H score55 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

About this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...

CISA orders federal mitigation of CVE-2026-16812

Public Sector Action
H score36 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

About this happening: CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate it by July 30, 2...

Timeline

  1. 22.09.2026 15:29 1 articles · 3h ago

    Arista says CVE-2026-93952 is actively exploited in VeloCloud Orchestrator

    Initial Disclosure

    Arista said CVE-2026-93952 is actively exploited against on-premises VeloCloud Orchestrator (VCO) deployments that use certificate-based authentication. The flaw can let a remote attacker with no login access privilege internal functions, affect the VCO host, and potentially reach the Edge devices managed by the orchestrator.

    Show sources
  2. 22.09.2026 15:29 2 articles · 3h ago

    Arista releases fixed VeloCloud Orchestrator builds for 5.2 and 6.4 trains

    Mitigation Patch Update

    As of September 22, Arista had released fixed VeloCloud Orchestrator (VCO) builds for the 5.2 and 6.4 trains and had already patched the Hosted and Dedicated versions of VCO. Supported 6.1 and 7.0 trains still lacked fixes, and customers on unsupported trains were told to contact Arista's TAC about upgrade options.

    Show sources