Cyber Resilience
← All news
Confirmed

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

Our takeArista reports active exploitation of CVE-2026-93952 (CVSS 10.0) in on-premises VeloCloud Orchestrator using certificate auth for Edges. Claimed — unconfirmed; no CISA KEV or filing yet. If you run VCO yourself, treat it as weaponized and patch immediately.
Sources (5)
What this means for you — Security leader:Arista Networks confirmed active exploitation of CVE-2026-93952 (CVSS 10.0) in on-prem VeloCloud Orchestrator versions 5.2.0–5.2.3.15, 6.1.0–6.1.3.7, 6.4.0–6.4.2.7 and 7.0.0–7.0.0.2 when using certificate-based Edge authentication. Patch to a fixed release immediately and treat internet-exposed VCO instances as compromised until validated.
What this means for you — Lean IT orgs:If you run an on-premises VeloCloud Orchestrator server that uses certificate authentication for your SD-WAN Edges, update it to a fixed version right away. Most smaller teams using the hosted VeloCloud service or non-certificate setups are not affected and can ignore this.
What this means for you — MSP:Audit every client running on-prem VeloCloud Orchestrator (versions listed in AV26-947) that uses certificate-based authentication; patch immediately and assume internet-facing instances may already be compromised. Hosted VeloCloud clients and non-certificate setups are unaffected.
What this means for you — Researcher:Arista Networks and CCCS confirm active exploitation of CVE-2026-93952 (CVSS 10.0) in on-prem VeloCloud Orchestrator using certificate auth. Fixed releases are available; the window for unauthenticated remote privilege escalation on exposed orchestrators is now closed only for those who have patched.