Arista VeloCloud CVSS 10.0 Flaw Added to CISA KEV
CISA added CVE-2026-93952, a CVSS 10.0 unauthenticated RCE flaw in Arista VeloCloud Orchestrator, to its KEV catalog September 22. Federal agencies have until September 25 to patch.

CISA added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog on September 22: a CVSS 10.0 remote code execution flaw in Arista’s on-premises VeloCloud Orchestrator (VCO). Federal civilian agencies have until September 25 to patch or apply mitigations under BOD 26-04. On-premises operators outside the federal space have active exploitation to contend with, which tends to concentrate the mind more effectively than a regulatory deadline.
This is the second VeloCloud Orchestrator flaw to reach the KEV catalog in roughly two months. CVE-2026-16812 hit KEV in late July; now CVE-2026-93952, at maximum CVSS severity, joins it.
The vulnerability
CVE-2026-93952 is an improper input validation flaw in the VCO web interface. An unauthenticated attacker with network access to that interface can invoke privileged internal functions and affect the host OS directly. Arista’s security advisory, published September 22, confirms the flaw “was discovered externally and is known to be actively exploited.”
One scope note worth leading with for triage: only on-premises VCO instances that use certificate-based authentication for Edge devices are affected. Hosted and Dedicated VCO deployments were patched on the back end before the public disclosure. If you run hosted or dedicated, this is not your fire drill today.
Affected versions and fixes
| Branch | Vulnerable through | Fixed in |
|---|---|---|
| 5.2 | 5.2.3.15 | 5.2.3.16 |
| 6.1 | 6.1.3.7 | Pending |
| 6.4 | 6.4.2.7 | 6.4.2.8 |
| 7.0 | 7.0.0.2 | Pending |
For the 5.2 and 6.4 trains, patches are out now: update immediately. For 6.1 and 7.0, Arista says fixes are “forthcoming for supported release trains,” so watch the advisory page. While you wait, restricting network access to the VCO management interface is the right interim control; there is no clean reason that interface should be broadly reachable in the first place.
Two flaws, two months, same platform
VeloCloud Orchestrator is the management plane for all connected SD-WAN Edge devices. A compromised orchestrator is not just a compromised server; it is a position from which every managed Edge is potentially reachable. Two KEV-tracked flaws in the same platform across a two-month span is a signal worth reading carefully: how broadly accessible is your VCO interface, and when did you last audit that?
CISA’s forensics triage guidance under BOD 26-04 applies to federal agencies. For the rest: the active exploitation flag is the deadline that matters.
Related: Zyxel, Veeam Flaws Confirmed Under Active Exploitation
- [ CRITICAL ]CVE-2026-93952Arista VeloCloud Orchestrator Unauthenticated RCE
Found this useful? Share it.
