ARISTA has issued urgent patches for a critical vulnerability in on-premises VeloCloud Orchestrator (VCO), its central management platform for VeloCloud SD-WAN edge devices, policies and traffic. Tracked as CVE-2026-93952 and rated 10.0 on the CVSS scale, the flaw is an improper input-validation issue that can let remote attackers access privileged internal functionality, potentially affecting the orchestrator’s confidentiality, integrity and availability. Arista said the vulnerability was discovered externally and is being actively exploited as a zero-day.
The issue affects only VeloCloud Orchestrator On-Prem, formerly known as VeloCloud Orchestrator by Broadcom. It is exposed when certificate-based authentication from VeloCloud Edge to VCO is configured: an attacker needs access to the public portion of the authentication certificate and network access to the VCO web interface, but does not need tenant or operator credentials. Arista fixed the flaw in VCO 5.2.3.16 and 6.4.2.8, for the 5.2.x and 6.1.x trains respectively, with patches for other trains planned.
Administrators are urged to upgrade, although restricting access to the web interface lowers exposure. The company said there are no definitive indicators of compromise and recommended reviewing VCO web access, backend application and system logs for suspicious activity. CVE-2026-93952 was added to CISA’s Known Exploited Vulnerabilities catalogue on Tuesday, with federal agencies given three days to patch under BOD 26-04.