CISA KEV Alert 22 Sept 2026, 20:30 UTC

CISA Warns of Active Attacks on Critical VeloCloud Flaw

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA added CVE-2026-93952 to its Known Exploited Vulnerabilities (KEV) catalogue on 22 September 2026. The vulnerability affects Arista VeloCloud Orchestrator (VCO) on-prem and is an improper input validation flaw that may expose privileged internal functionality and affect the VCO host.

The flaw can be exploited remotely. Successful exploitation may compromise the confidentiality, integrity and availability of the orchestrator and data it manages. NVD rates the vulnerability CVSS 10.0 (Critical). Patch availability is currently unknown.

CISA’s KEV listing confirms active exploitation. The data does not confirm use in ransomware campaigns. CISA set a remediation deadline of 25 September 2026.

CISA requires organisations to apply mitigations in accordance with Arista’s instructions, while following BOD 26-04 guidance on prioritising security updates and its Forensics Triage Requirements. FCEB agencies are directly affected by this requirement. Organisations should assess each asset’s internet exposure, apply the relevant patching guidance, or discontinue use if mitigations are unavailable.

See the NVD entry and CISA KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline