CVE Tools

Arista Urges Immediate Patching of Exploited VCO Zero-Day

SecurityWeekBy Ionut Arghire

Reported exploitedVeloCloud Orchestrator

Our summary

Arista has released emergency fixes for CVE-2026-93952, a CVSS 10 improper input validation flaw actively exploited against on-premises VeloCloud Orchestrator deployments. The issue can let a remote attacker reach privileged internal functions, potentially compromising the confidentiality, integrity, and availability of the orchestrator and its managed data. Arista fixed the affected 5.2.x and 6.1.x trains in VCO versions 5.2.3.16 and 6.4.2.8, respectively, and advises organizations to update immediately.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store