Arista patches actively exploited VeloCloud Orchestrator zero-day
Reported exploitedVeloCloud OrchestratorOur summary
Arista Networks has issued patches for CVE-2026-93952, an actively exploited zero-day in VeloCloud Orchestrator (VCO) On-Prem deployments using certificate-based VeloCloud Edge-to-VCO authentication. The input-validation flaw can let remote attackers with network access to the VCO web interface reach privileged internal host functions without VCO credentials; hosted VCO 5.2.3.16 or later and VCO 6.4.2.8 or later are patched, while fixes are planned for 6.1.3.7 and below and 7.0.0.2 and below.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.