CVSS 10.0 Flaw in VeloCloud Orchestrator Actively Exploited, Patches Available
A critical vulnerability, CVE-2026-93952, with a maximum CVSS score of 10.0 has been confirmed actively exploited in on-premises VeloCloud Orchestrator (VCO) by Arista Networks. The flaw stems from improper input validation in the VCO web interface, allowing attackers to gain access without operator credentials under certain network conditions. Affected versions include builds 5.2.3.15 and earlier, 6.1.3.7 and below, 6.4.2.7 and below, and 7.0.0.2 and below, while fixed builds 5.2.3.16 and 6.4.2.8 are now available. Cloud-hosted VCO instances were automatically patched and are not affected, but on-premises deployments managing branch SD-WAN infrastructure remain at risk. Security teams are advised to patch immediately, monitor for anomalous files such as vcnode.js, rotate exposed credentials, and establish clear incident response procedures including isolation authority and rebuild plans.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in