Arista security patch release for CVE-2026-93952
Security Patch Release
Summary
Hide ▲
Show ▼
Arista released fixed VeloCloud Orchestrator (VCO) builds for the 5.2 and 6.4 trains, reducing exposure for deployments tied to CVE-2026-93952. The patch set covers on-premises and Hosted/Dedicated VCO versions, while 6.1 and 7.0 were still awaiting fixes as of September 22. The release matters because VCO manages Edge devices in VeloCloud SD-WAN and compromise can extend beyond the orchestrator itself.
Related Happenings
Arista mitigation guidance for Arista VeloCloud Orchestrator compensating controls for CVE-2026-93952
Advisory/Mitigation
H score53
First: 22.09.2026 15:29
Last: 22.09.2026 15:29
Sources 1
How related:
Until a fixed release is installed, Arista recommends these steps:
About this happening:
Arista issued temporary mitigation steps for exposed VeloCloud Orchestrator (VCO) deployments while a fixed release is pending, limiting the risk from actively exploited...
Arista mitigation guidance for Arista VeloCloud Orchestrator compensating controls for CVE-2026-93952
Advisory/MitigationHow related: Until a fixed release is installed, Arista recommends these steps:
About this happening: Arista issued temporary mitigation steps for exposed VeloCloud Orchestrator (VCO) deployments while a fixed release is pending, limiting the risk from actively exploited...
GitLab CE/EE security update for CVE-2026-85706
Security Patch Release
H score44
First: 14.09.2026 10:06
Last: 14.09.2026 10:06
Sources 1
About this happening:
GitLab released CE/EE fixes for CVE-2026-85706, and users were urged to patch immediately to close a repository commits API flaw that can expose credentials and se...
GitLab CE/EE security update for CVE-2026-85706
Security Patch ReleaseAbout this happening: GitLab released CE/EE fixes for CVE-2026-85706, and users were urged to patch immediately to close a repository commits API flaw that can expose credentials and se...
Gitea security patch release for CVE-2026-59774
Security Patch Release
H score65
First: 05.08.2026 14:04
Last: 05.08.2026 14:04
Sources 1
About this happening:
Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...
Gitea security patch release for CVE-2026-59774
Security Patch ReleaseAbout this happening: Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch Release
H score55
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
About this happening:
Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch ReleaseAbout this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
CISA orders federal mitigation of CVE-2026-16812
Public Sector Action
H score36
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
About this happening:
CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate it by July 30, 2...
CISA orders federal mitigation of CVE-2026-16812
Public Sector ActionAbout this happening: CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate it by July 30, 2...
Timeline
-
22.09.2026 15:29 1 articles · 3h ago
Arista says CVE-2026-93952 is actively exploited in VeloCloud Orchestrator
Initial DisclosureArista said CVE-2026-93952 is actively exploited against on-premises VeloCloud Orchestrator (VCO) deployments that use certificate-based authentication. The flaw can let a remote attacker with no login access privilege internal functions, affect the VCO host, and potentially reach the Edge devices managed by the orchestrator.
Show sources
- New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups — thehackernews.com — 22.09.2026 15:29
-
22.09.2026 15:29 2 articles · 3h ago
Arista releases fixed VeloCloud Orchestrator builds for 5.2 and 6.4 trains
Mitigation Patch UpdateAs of September 22, Arista had released fixed VeloCloud Orchestrator (VCO) builds for the 5.2 and 6.4 trains and had already patched the Hosted and Dedicated versions of VCO. Supported 6.1 and 7.0 trains still lacked fixes, and customers on unsupported trains were told to contact Arista's TAC about upgrade options.
Show sources
- New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups — thehackernews.com — 22.09.2026 15:29
- New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups — thehackernews.com — 22.09.2026 15:29