securityonline.info 22 Sept 2026, 03:14 UTC

Arista Warns Attackers Are Exploiting Critical VeloCloud Flaw

Arista Warns Attackers Are Exploiting Critical VeloCloud Flaw
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

ON 22 September 2026, Arista Networks warned that attackers were actively exploiting CVE-2026-93952, a critical vulnerability in on-premises VeloCloud Orchestrator. The flaw has a CVSS score of 10.0. Arista said it was discovered externally and was being exploited in the wild, although no public proof-of-concept code had been confirmed.

Successful exploitation can provide access to privileged internal functionality and affect the VeloCloud host, potentially allowing attackers to alter configurations across managed networks.

The issue involves improper input validation in the orchestrator’s web interface. According to the supplied report, exploitation requires certificate-based authentication between edge appliances and the orchestrator, access to the public portion of the edge authentication certificate, and the ability to send untrusted input to the interface. No existing operator credentials are required. Reported post-compromise activity includes installing backdoor services such as `vcnode.js` and creating persistence files in system directories.

Affected on-premises versions include 5.2.3.15 and earlier, 6.1.3.7 and earlier, 6.4.2.7 and earlier, and 7.0.0.2 and earlier. Arista has released version 5.2.3.16 and version 6.4.2.8 as fixes; organisations on other unsupported release trains are advised to contact customer support. Cloud-hosted VeloCloud versions have reportedly been patched automatically, while standard Arista EOS switches are unaffected.

Where immediate updating is not possible, administrators should restrict web access to trusted internal networks and review logs, including nginx requests containing unusual `x-vc-opt` headers and suspicious outbound connections.

View full article

Article by CyberSIXT