New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Reported exploitedVeloCloud OrchestratorOur summary
Arista Networks says attackers are actively exploiting CVE-2026-93952, a CVSS 10.0 vulnerability in on-premises VeloCloud Orchestrator deployments using certificate-based Edge authentication. A remote unauthenticated attacker with network access to the VCO web interface and an Edge certificate's public portion could access privileged internal functions, compromise the orchestrator, and potentially reach managed Edge devices. Fixed releases are available for 5.2 and 6.4, while fixes for affected 6.1 and 7.0 releases are pending; organizations should restrict VCO web access and monitor for signs of compromise.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.