Over 6,000 VeloCloud Orchestrators Exposed Online Amid Actively Exploited CVE-2026-93952
CVE-2026-93952 is a maximum-severity (CVSS 10.0) vulnerability affecting on-premises VeloCloud Orchestrator (VCO), which Arista Networks has confirmed is actively being exploited in the wild. Internet scanning data from ZoomEye, queried on September 22, 2026, identified approximately 6,050 internet-reachable systems returning VeloCloud-related HTTP content, indicating significant public exposure of what should be a tightly restricted management plane. The figure reflects reachable systems bearing the VeloCloud fingerprint, not a confirmed count of vulnerable builds, as version ranges and deployment models cannot be determined from fingerprinting alone. Affected versions include VCO 5.2.3.15 and earlier, 6.1.3.7 and below, 6.4.2.7 and below, and 7.0.0.2 and below, while cloud-hosted instances were patched automatically and are not at risk. Administrators are advised to upgrade to a fixed build, restrict the VCO web interface to trusted internal networks, and audit systems for indicators of compromise such as the vcnode.js backdoor script.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in