Back to blog
CVE-2026-93952AristaVeloCloudVeloCloud OrchestratorSD-WANCISA KEVCVE

Arista VeloCloud Orchestrator CVE-2026-93952: 10.0 in CISA KEV, Only On-Prem Must Act

CVE-2026-93952 (10.0) on on-prem VeloCloud Orchestrator, in CISA KEV. Second VCO KEV entry in two months; hosted instances are already patched.

September 24, 20263 min read

CVE-2026-93952 targets Arista VeloCloud Orchestrator (VCO) in on-prem deployments. Rated 10.0, published and added to the CISA KEV catalog on September 22, 2026, with a deadline of the 25th.

It's the second VCO CVE in KEV in two months, after CVE-2026-16812 in July.

FieldValue
CVSS 3.110.0 (CRITICAL)
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
NVD published2026-09-22
CISA KEV added2026-09-22
CISA deadline2026-09-25

Who Has to Act

Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

The advisory's most useful sentence: if your orchestrator is hosted by Arista (shared or dedicated), the fix is already applied. Only organisations running their own VCO instance — managed service providers, large enterprises, regulated sectors — have work to do.

The Vulnerability

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

CISA classes it as improper input validation. No mechanism detail has been published, and I won't invent one.

The S:C (scope changed) and "data managed by the orchestrator" say what matters: the impact extends beyond the orchestrator.

Why the SD-WAN orchestrator is the worst possible target

The VeloCloud orchestrator pushes configuration to every SD-WAN edge on the network — that is, to every site of the organisation. Controlling it yields:

  • the complete topology and configuration of every site
  • the ability to alter routing: send a branch's traffic through a point the attacker controls
  • the ability to push configuration to hundreds of devices in one operation
  • for a managed service provider, access to all its customers at once

Versions

NVD lists these bounds for velocloud_orchestrator: 5.2.3.16, 6.1.3.7, 6.4.2.8 and 7.0.0.2. They're per-branch bounds from NVD; the Arista advisory gives the fixed release to install for each.


Detection

  • Operators and accounts recently created or elevated in the orchestrator
  • Configuration changes pushed to edges outside change windows — the most important signal
  • Modified profiles or routing policies, especially backhaul or gateway rules
  • Abnormal activity on the orchestrator host: processes, files, outbound connections

Mitigation

  1. Hosted instances: nothing to do for this CVE, already fixed by Arista.
  2. On-prem instances: apply the fixed release for your branch — the CISA deadline was September 25.
  3. Restrict access to the orchestrator interface: it should only be reachable from admin networks and by the edges.
  4. If compromised: audit the configuration pushed to every edge, rotate operator credentials, activation keys and certificates.

Why Continuous Monitoring of Network Orchestration Matters

Two critical KEV CVEs in two months on the same orchestrator, and each time the same question: which version runs on the on-prem instance nobody has touched since installation?

With cveo.tech, inventory your network orchestrators and controllers with exact versions, and get alerted whenever a KEV-listed CVE affects them.

Every Monday

The week's critical CVEs, in your inbox

One email a week: the CVSS ≥ 9 vulnerabilities published in the last seven days, plus our latest analyses. Nothing else.

Double opt-in by email. Unsubscribe in one click, any time.

Monitor CVEs with AI

AI-powered search, CVSS scoring, asset monitoring and automatic alerts.