#Velocloud
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments.
Arista patches actively exploited VeloCloud Orchestrator zero-day
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments.
www.bleepingcomputer.com
September 23, 2026 at 12:30 PM
Arista acquires VMware’s VeloCloud SD-WAN outfit from Broadcom
Arista acquires VMware’s VeloCloud SD-WAN outfit from Broadcom
It's 2025 so even this networking deal is about AI, which is apparently about to change wide area networks Broadcom has sold VeloCloud, the software-defined WAN business VMware acquired in 2017, to Arista.…
dlvr.it
July 2, 2025 at 4:36 AM
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups thehackernews.com/2026/09/new-...
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Attackers are exploiting CVE-2026-93952 in certificate-authenticated VeloCloud Orchestrators, with some release trains still awaiting fixes.
thehackernews.com
September 27, 2026 at 9:42 PM
Aktuell laufen Angriffe auf Sicherheitslücken in F5 BIG-IP APM, Check-Point-Produkte und Arista VeloCloud Orchestrator. #Security
Cyberangriffe auf F5 BIG-IP, Check Point Security und Arista VeloCloud
Aktuell laufen Angriffe auf Sicherheitslücken in F5 BIG-IP APM, Check-Point-Produkte und Arista VeloCloud Orchestrator.
www.heise.de
September 23, 2026 at 6:40 AM
Daily IT Security Digest — 2026-09-28
Bot](https://mastodon.social/@EUVD_Bot/117349264750184542)

**6. Arista VeloCloud Orchestrator Zero-Day — Actively Exploited**
Arista's VeloCloud Orchestrator (on-premise versions below 5.2.3.16 and 6.4.2.8) is targeted by an active, critical zero-day exploit
September 28, 2026 at 3:37 PM
SANS Stormcast Wednesday, September 23rd, 2026: GET with Body; Checkpoint, VeloCloud, BigIP and Microsoft Defender 0-days
https://isc.sans.edu/podcastdetail/10106
September 23, 2026 at 2:40 AM
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22.

The flaw, tracke…
#hackernews #news
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are
thehackernews.com
September 23, 2026 at 6:05 AM
U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exp…
#hackernews #news
U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-85102 resides in the VPN negotiation process and lets an unauthenticated attacker bypass security checks […]
securityaffairs.com
September 24, 2026 at 7:37 PM
Four actively exploited perimeter flaws hit CISA's KEV list: Check Point, Arista VeloCloud, and F5 BIG-IP. https://intel.threadlinqs.com/threat/TL-2026-2678 #ThreatIntel #CVE_2026_85102 #CVE_2026_93616 #CISAKEV
September 27, 2026 at 3:52 AM
Arista VeloCloud Orchestrator - Actively Exploited Critical Vulnerability
URL: www.arista.com/en/support/a...
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 10.0
Security Advisory 0183 - Arista
September 22, 2026 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successfu...
www.arista.com
September 23, 2026 at 4:10 AM
Blog: "Arista corrige vulnerabilidad zero-day explotada en VeloCloud Orchestrator"
Arista corrige vulnerabilidad zero-day explotada en VeloCloud Orchestrator
Blog sobre informática, tecnología y seguridad con manuales, tutoriales y documentación sobre herramientas y programas
blog.elhacker.net
September 25, 2026 at 6:02 AM
On-prem VeloCloud Orchestrator under attack, only some versions patched
A flaw in VeloCloud Orchestrator enables attackers to access the platform organizations use to manage their VeloCloud SD-WAN subscriptions and the edge devices it controls. Arista, which now owns the VeloCloud business, warned customers that a vulnerable configuration exists in on-premises VeloCloud Orchestrator deployments that remote attackers may abuse to access “privileged internal functionality” and impact the VSO host. The flaw also affected Arista’s Hosted and Dedicated VCO deployments, but the company has now patched them. “This issue was discovered externally and is known to be actively exploited,” Arista said in its advisory, urging customers to upgrade to a patched release of VCO immediately — although fixes are currently available only for some of the affected versions. Mayuresh Dani, security research manager, at Qualys Threat Research Unit, warned that unpatched versions remain “exposed to active exploitation and have only compensating controls as a protection.” Arista said that organizations suspecting compromise should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible. Andrew Costis, engineering manager of the adversary research team at AttackIQ, backs that advice. “Patching closes the door but doesn’t reverse what came through it. A compromised orchestrator can reach the Edge devices it manages, rotate credentials and validate device state across sites,” he said. ## Exploitation limited to a configuration Arista is tracking the flaw as CVE-2026-93952, an improper input validation issue with a critical CVSS rating of 10.0. An attack will only work under certain conditions, though: A VCO deployment is exposed only if certificate-based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured, and the attacker has the public key of the VeloCloud Edge authentication certificate and also network access to the VCO web interface. Attackers do not need VCO tenant or operator credentials. “Based on the information available, this is most certainly a cross-site request forgery (CSRF) vulnerability that allows threat actors to use an Edge certificate to bypass the front-end and forward the request to internal services, which inherently trusts this information,” Dani said. The affected versions span four VCO release trains: 5.2.3.15 and earlier in the 5.2.x train, 6.1.3.7 and earlier in 6.1.x, 6.4.2.7 and earlier in 6.4.x, and 7.0.0.2 and earlier in 7.0. x. Arista has released fixes in VCO versions 5.2.3.16 and later in the 5.2.3 train and 6.4.2.8 and later in the 6.4.2 train. Fixes for the others trains are still to come. ## What defenders can do For organizations that cannot immediately upgrade, Arista recommends restricting access to the VCO web interface to trusted administrative networks and monitoring for suspicious activities including known malicious source IPs, unexpected outbound network activity, backdoor daemons and webshells, and unexpected admin changes. “Because successful exploitation may compromise the orchestrator host and data managed by the orchestrator, operators should follow incident-response guidance appropriate for their deployment,” the company added. The advisory also shared a few indicators of compromise, including a suspicious “vc-sysmond” file, the “x-vc-opt “ HTTP header and two source IP addresses associated with exploitation activity. AttackIQ’s Costis said Arista’s advice underlined the need for continuous threat exposure management and adversarial exposure validation: “Knowing which orchestrators are reachable, and proving your access restrictions actually hold, is worth far more before an advisory like this lands than after.” This is the second maximum-severity VeloCloud flaw that Arista has had to patch this year. The company patched another actively exploited bug in the platform in July. _This article first appeared on_ Network World_._
www.csoonline.com
September 24, 2026 at 3:42 PM
On-prem VeloCloud Orchestrator under attack, only some versions patched
A flaw in VeloCloud Orchestrator enables attackers to access the platform organizations use to manage their VeloCloud SD-WAN subscriptions and the edge devices it controls. Arista, which now owns the VeloCloud business, warned customers that a vulnerable configuration exists in on-premises VeloCloud Orchestrator deployments that remote attackers may abuse to access “privileged internal functionality” and impact the VSO host. The flaw also affected Arista’s Hosted and Dedicated VCO deployments, but the company has now patched them. “This issue was discovered externally and is known to be actively exploited,” Arista said in its advisory, urging customers to upgrade to a patched release of VCO immediately — although fixes are currently available only for some of the affected versions. Mayuresh Dani, security research manager, at Qualys Threat Research Unit, warned that unpatched versions remain “exposed to active exploitation and have only compensating controls as a protection.” Arista said that organizations suspecting compromise should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible. Andrew Costis, engineering manager of the adversary research team at AttackIQ, backs that advice. “Patching closes the door but doesn’t reverse what came through it. A compromised orchestrator can reach the Edge devices it manages, rotate credentials and validate device state across sites,” he said. ## Exploitation limited to a configuration Arista is tracking the flaw as CVE-2026-93952, an improper input validation issue with a critical CVSS rating of 10.0. An attack will only work under certain conditions, though: A VCO deployment is exposed only if certificate-based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured, and the attacker has the public key of the VeloCloud Edge authentication certificate and also network access to the VCO web interface. Attackers do not need VCO tenant or operator credentials. “Based on the information available, this is most certainly a cross-site request forgery (CSRF) vulnerability that allows threat actors to use an Edge certificate to bypass the front-end and forward the request to internal services, which inherently trusts this information,” Dani said. The affected versions span four VCO release trains: 5.2.3.15 and earlier in the 5.2.x train, 6.1.3.7 and earlier in 6.1.x, 6.4.2.7 and earlier in 6.4.x, and 7.0.0.2 and earlier in 7.0. x. Arista has released fixes in VCO versions 5.2.3.16 and later in the 5.2.3 train and 6.4.2.8 and later in the 6.4.2 train. Fixes for the others trains are still to come. ## What defenders can do For organizations that cannot immediately upgrade, Arista recommends restricting access to the VCO web interface to trusted administrative networks and monitoring for suspicious activities including known malicious source IPs, unexpected outbound network activity, backdoor daemons and webshells, and unexpected admin changes. “Because successful exploitation may compromise the orchestrator host and data managed by the orchestrator, operators should follow incident-response guidance appropriate for their deployment,” the company added. The advisory also shared a few indicators of compromise, including a suspicious “vc-sysmond” file, the “x-vc-opt “ HTTP header and two source IP addresses associated with exploitation activity. AttackIQ’s Costis said Arista’s advice underlined the need for continuous threat exposure management and adversarial exposure validation: “Knowing which orchestrators are reachable, and proving your access restrictions actually hold, is worth far more before an advisory like this lands than after.” This is the second maximum-severity VeloCloud flaw that Arista has had to patch this year. The company patched another actively exploited bug in the platform in July.
www.networkworld.com
September 24, 2026 at 6:04 PM
Daily IT Security Digest — 2026-09-28
(CVE-2026-93952) that allows unauthenticated remote attackers to access privileged functions. Organizations running on-prem VeloCloud deployments must patch immediately and review system logs for any signs of unauthorized access.
Source:
September 28, 2026 at 3:37 PM
📰 Arista Rilis Patch untuk Zero-Day VeloCloud Orchestrator yang Aktif Dieksploitasi

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/09/24/cve-2026-93952-velocloud-orchestrator-zero-day/

#arista #cisa #cve #cybersecurity #keamananJaringan #sd-wan #velocloud #velocloudOrchestrator #
September 24, 2026 at 4:00 AM
Arista patches actively exploited VeloCloud Orchestrator zero-day

Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. [...]
#hackernews #news
Arista patches actively exploited VeloCloud Orchestrator zero-day
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. [...]
www.bleepingcomputer.com
September 24, 2026 at 10:19 AM
Hackers are exploiting a CVSS 10 RCE in Arista VeloCloud Orchestrator on-prem servers

www.arista.com/en/support/a...

www.cisa.gov/news-events/...
Security Advisory 0144 - Arista
July 27, 2026 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exp...
www.arista.com
July 28, 2026 at 11:58 AM
Arista VeloCloud Orchestrator: 2nd CVSS-10.0 CVE in 3 months. CVE-2026-93952 gives unauthenticated privileged access, actively exploited. Patch to 5.2.3.16+/6.4.2.8+ now. On 6.1.x/7.0.x? Call Arista TAC.
🇬🇧 diesec.com/2026/09/aris...
🇩🇪 diesec.com/de/2026/09/a...
#cybersecurity
September 28, 2026 at 8:00 AM
D-Link Routers, VeloCloud, and Veeam Under Active Attack

Today's cybersecurity update for September 22nd, 2026 covers six critical security issues that small business owners need to address immediately.

https://youtu.be/OvoBdoS77Vw
September 22, 2026 at 4:01 PM