Your on-prem SD-WAN brain is now a CVSS 10 KEV with a Friday due date. Arista’s VeloCloud Orchestrator flaw is actively exploited, hosted tenants are already patched, and on-prem operators still need to move — plus hunt for a known backdoor hash.
What happened
On September 22, 2026, Arista published Security Advisory 0183 for CVE-2026-93952: improper input validation in on-prem VeloCloud Orchestrator (VCO) that can let a remote attacker reach privileged internal functionality and impact the VCO host. CVSSv3.1 base score: 10.0. The issue was discovered externally and is known to be actively exploited. Hosted/Dedicated VCO was impacted and Arista says those are already patched.
Required config for exploitation: certificate-based Edge→VCO authentication, network access to the VCO web UI, and access to the public portion of the Edge auth certificate. Tenant/operator credentials are not required. CISA added the CVE to KEV the same day; federal due September 25, 2026; forensic triage required.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters
Compromise the orchestrator and you inherit the SD-WAN fabric — configs, credentials, certificates, and a path into managed Edges. Arista’s own post-remediation note: Edge access may follow. This is not “a UI bug”; it is the control plane for branch connectivity.
What to do first
- Confirm on-prem VCO version against affected trains: ≤5.2.3.15, ≤6.1.3.7, ≤6.4.2.7, ≤7.0.0.2.
- Upgrade to fixed builds where available: 5.2.3.16+ or 6.4.2.8+; contact TAC for other trains.
- Until patched: restrict VCO web UI to trusted admin networks; monitor outbound from the VCO host; block unused egress.
- Hunt IoCs before you wipe the box:
/usr/local/sbin/.vcnode.js,/usr/local/sbin/vc-sysmond(md5dc78e206eaeadec59fc5801fe4556bd0),vc-sysmon.service, nginx logs withx-vc-opt, and source IPs 142.93.149.77 / 104.248.126.159. - If compromise suspected: preserve logs, rotate credentials/certs, validate Edge state, rebuild orchestrator from trusted media.
Details
- CVE: CVE-2026-93952 (CVSS 10.0 / CVSSv4 9.5; CWE-20)
- Product: Arista VeloCloud Orchestrator on-prem (formerly Broadcom VCO)
- KEV: Added 2026-09-22; federal due 2026-09-25; forensic triage Yes
- Advisory: Security Advisory 0183
- Ransomware use (CISA): Unknown
Hunt / verify
- Verify running VCO build ≥ fixed release for your train.
- Review VCO web, backend, and system logs for unusual URL paths, encoded characters, internal service references, and high request rates.
- Check for the listed backdoor files/hash and
x-vc-optheader hits. - Audit recent privileged maintenance actions and config exports that lack an admin owner.
Sources
- https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-93952
- https://www.cve.org/CVERecord?id=CVE-2026-93952
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.