CISA added CVE-2026-93952 to its Known Exploited Vulnerabilities (KEV) catalogue on 22 September 2026. The vulnerability affects Arista VeloCloud Orchestrator (VCO) on-prem and is an improper input validation flaw that may expose privileged internal functionality and affect the VCO host.
The flaw can be exploited remotely. Successful exploitation may compromise the confidentiality, integrity and availability of the orchestrator and data it manages. NVD rates the vulnerability CVSS 10.0 (Critical). Patch availability is currently unknown.
CISA’s KEV listing confirms active exploitation. The data does not confirm use in ransomware campaigns. CISA set a remediation deadline of 25 September 2026.
CISA requires organisations to apply mitigations in accordance with Arista’s instructions, while following BOD 26-04 guidance on prioritising security updates and its Forensics Triage Requirements. FCEB agencies are directly affected by this requirement. Organisations should assess each asset’s internet exposure, apply the relevant patching guidance, or discontinue use if mitigations are unavailable.
See the NVD entry and CISA KEV catalogue for full details.