CISA Flags Arista VeloCloud Orchestrator Flaw as Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog on 22 September 2026. The vulnerability affects Arista VeloCloud Orchestrator, a management and policy platform for SD-WAN networks, and stems from improper input validation. Because the orchestrator distributes configurations, manages tunnels, and holds credentials for connected edge devices, a successful exploit could give attackers broad control over an organisation's network. CISA's listing shifts the priority for operators from evaluating whether to patch to determining how quickly remediation can be completed. Recommended immediate steps include auditing orchestrator logs for anomalous activity, rotating credentials, and verifying that the management interface is not publicly accessible.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in