VeloCloud Orchestrator certificate-based privilege escalation (CVE-2026-93952)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-93952 is an actively exploited flaw in VeloCloud Orchestrator (VCO) that can let a remote attacker with no login access privilege internal functions and compromise the orchestrator. Exposure is limited to orchestrators configured for certificate-based authentication from VeloCloud Edge devices, and a successful attack can also reach the managed Edge devices. Arista had fixed releases for the 5.2 and 6.4 trains as of September 22, while 6.1 and 7.0 were still awaiting fixes.
Related Happenings
Arista mitigation guidance for Arista VeloCloud Orchestrator compensating controls for CVE-2026-93952
Advisory/Mitigation
H score53
First: 22.09.2026 15:29
Last: 22.09.2026 15:29
Sources 1
How related:
Until a fixed release is installed, Arista recommends these steps:
About this happening:
Arista issued temporary mitigation steps for exposed VeloCloud Orchestrator (VCO) deployments while a fixed release is pending, limiting the risk from actively exploited...
Arista mitigation guidance for Arista VeloCloud Orchestrator compensating controls for CVE-2026-93952
Advisory/MitigationHow related: Until a fixed release is installed, Arista recommends these steps:
About this happening: Arista issued temporary mitigation steps for exposed VeloCloud Orchestrator (VCO) deployments while a fixed release is pending, limiting the risk from actively exploited...
CISA orders federal mitigation of CVE-2026-16812
Public Sector Action
H score36
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
About this happening:
CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate it by July 30, 2...
CISA orders federal mitigation of CVE-2026-16812
Public Sector ActionAbout this happening: CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate it by July 30, 2...
VeloCloud Orchestrator unauthenticated OS command injection, actively exploited (CVE-2026-16812)
Vulnerability
H score48
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
About this happening:
CVE-2026-16812 is a maximum-severity unauthenticated OS command injection in Arista VeloCloud Orchestrator (VCO) on-premises that is being actively exploited. The...
VeloCloud Orchestrator unauthenticated OS command injection, actively exploited (CVE-2026-16812)
VulnerabilityAbout this happening: CVE-2026-16812 is a maximum-severity unauthenticated OS command injection in Arista VeloCloud Orchestrator (VCO) on-premises that is being actively exploited. The...
Timeline
-
22.09.2026 15:29 2 articles · 3h ago
Arista says CVE-2026-93952 is actively exploited in certificate-based VeloCloud Orchestrator deployments
Initial DisclosureArista said CVE-2026-93952 is actively exploited against on-premises VeloCloud Orchestrator deployments that use certificate-based authentication from VeloCloud Edge devices. The flaw may let a remote attacker with no login access privilege internal functions, affect the VCO host, compromise orchestrator data, and reach the managed Edge devices. Arista also said fixed releases were available for the 5.2 and 6.4 release trains as of September 22, while 6.1 and 7.0 still lacked fixes, and that Hosted and Dedicated VCO versions had already been patched.
Show sources
- New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups — thehackernews.com — 22.09.2026 15:29
- New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups — thehackernews.com — 22.09.2026 15:29