Retour au blog
CVE-2026-93952AristaVeloCloudVeloCloud OrchestratorSD-WANCISA KEVCVE

Arista VeloCloud Orchestrator CVE-2026-93952: 10.0 in CISA KEV, Only On-Prem Must Act

CVE-2026-93952 (10.0) on on-prem VeloCloud Orchestrator, in CISA KEV. Second VCO KEV entry in two months; hosted instances are already patched.

24 septembre 20263 min de lecture

CVE-2026-93952 targets Arista VeloCloud Orchestrator (VCO) in on-prem deployments. Rated 10.0, published and added to the CISA KEV catalog on September 22, 2026, with a deadline of the 25th.

It's the second VCO CVE in KEV in two months, after CVE-2026-16812 in July.

FieldValue
CVSS 3.110.0 (CRITICAL)
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
NVD published2026-09-22
CISA KEV added2026-09-22
CISA deadline2026-09-25

Who Has to Act

Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

The advisory's most useful sentence: if your orchestrator is hosted by Arista (shared or dedicated), the fix is already applied. Only organisations running their own VCO instance — managed service providers, large enterprises, regulated sectors — have work to do.

The Vulnerability

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

CISA classes it as improper input validation. No mechanism detail has been published, and I won't invent one.

The S:C (scope changed) and "data managed by the orchestrator" say what matters: the impact extends beyond the orchestrator.

Why the SD-WAN orchestrator is the worst possible target

The VeloCloud orchestrator pushes configuration to every SD-WAN edge on the network — that is, to every site of the organisation. Controlling it yields:

  • the complete topology and configuration of every site
  • the ability to alter routing: send a branch's traffic through a point the attacker controls
  • the ability to push configuration to hundreds of devices in one operation
  • for a managed service provider, access to all its customers at once

Versions

NVD lists these bounds for velocloud_orchestrator: 5.2.3.16, 6.1.3.7, 6.4.2.8 and 7.0.0.2. They're per-branch bounds from NVD; the Arista advisory gives the fixed release to install for each.


Detection

  • Operators and accounts recently created or elevated in the orchestrator
  • Configuration changes pushed to edges outside change windows — the most important signal
  • Modified profiles or routing policies, especially backhaul or gateway rules
  • Abnormal activity on the orchestrator host: processes, files, outbound connections

Mitigation

  1. Hosted instances: nothing to do for this CVE, already fixed by Arista.
  2. On-prem instances: apply the fixed release for your branch — the CISA deadline was September 25.
  3. Restrict access to the orchestrator interface: it should only be reachable from admin networks and by the edges.
  4. If compromised: audit the configuration pushed to every edge, rotate operator credentials, activation keys and certificates.

Why Continuous Monitoring of Network Orchestration Matters

Two critical KEV CVEs in two months on the same orchestrator, and each time the same question: which version runs on the on-prem instance nobody has touched since installation?

With cveo.tech, inventory your network orchestrators and controllers with exact versions, and get alerted whenever a KEV-listed CVE affects them.

Chaque lundi

Les CVE critiques de la semaine, dans votre boîte mail

Un email par semaine : les vulnérabilités CVSS ≥ 9 publiées ces sept derniers jours, et nos dernières analyses. Rien d'autre.

Double confirmation par email. Désinscription en un clic, à tout moment.

Surveillez les CVE avec l'IA

Recherche IA, scoring CVSS, surveillance de parc et alertes automatiques.