Arista VeloCloud CVE-2026-93952: On-Prem Orchestrator CVSS 10 — KEV Due September 25

By George Bailey   Published: 09/22/26   Updated: 09/22/26   2 min read

Your on-prem SD-WAN brain is now a CVSS 10 KEV with a Friday due date. Arista’s VeloCloud Orchestrator flaw is actively exploited, hosted tenants are already patched, and on-prem operators still need to move — plus hunt for a known backdoor hash.

What happened

On September 22, 2026, Arista published Security Advisory 0183 for CVE-2026-93952: improper input validation in on-prem VeloCloud Orchestrator (VCO) that can let a remote attacker reach privileged internal functionality and impact the VCO host. CVSSv3.1 base score: 10.0. The issue was discovered externally and is known to be actively exploited. Hosted/Dedicated VCO was impacted and Arista says those are already patched.

Required config for exploitation: certificate-based Edge→VCO authentication, network access to the VCO web UI, and access to the public portion of the Edge auth certificate. Tenant/operator credentials are not required. CISA added the CVE to KEV the same day; federal due September 25, 2026; forensic triage required.

Why it matters

Compromise the orchestrator and you inherit the SD-WAN fabric — configs, credentials, certificates, and a path into managed Edges. Arista’s own post-remediation note: Edge access may follow. This is not “a UI bug”; it is the control plane for branch connectivity.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.