Critical Unauthenticated Flaw in Arista VeloCloud Orchestrator Exploited in the Wild
Arista has issued an urgent advisory warning that threat actors are actively exploiting a critical vulnerability in on-premises deployments of VeloCloud Orchestrator (VCO), the centralized platform used to manage Edge devices across VeloCloud software-defined wide area network (SD-WAN) environments. Tracked as CVE-2026-93952 with a maximum CVSS score of 10.0, the flaw allows unauthenticated remote attackers to execute privileged internal functions directly against the VCO host. The issue specifically impacts systems configured to authenticate Edge appliances using certificates. Fixed builds have been released for the 5.2 and 6.4 release branches, while patches for branches 6.1 and 7.0 remain pending.
Centralized network orchestration engines represent an exceptionally dangerous single point of failure. In modern SD-WAN and hybrid multi-cloud topologies, orchestrators do not merely handle logging or telemetry; they distribute cryptographic configurations, establish routing topologies, and provision dynamic overlay tunnels. A root-level compromise of the VCO host grants attackers systemic control over the entire fleet of managed Edge appliances. This allows adversaries to intercept corporate traffic, alter network segregation policies, or pivot seamlessly into private corporate workloads without tripping typical perimeter alarms.
This incident highlights a sustained shift in adversarial tradecraft toward exploiting network infrastructure and appliance management planes. As identity perimeters and endpoint detection tools have matured, attackers increasingly focus on on-premises network virtualization and SD-WAN controllers. These systems frequently reside in administrative trust zones yet require external connectivity to communicate with distributed edge nodes. This creates a high-value attack vector where software vulnerabilities can be weaponized into full control of enterprise data paths.
For DevOps, NetOps, and security engineering teams, immediate remediation is required. Organizations operating on-premises VCO deployments must identify whether certificate-based authentication is enabled and apply the 5.2 or 6.4 fixes immediately. For environments running the 6.1 or 7.0 trains where patches are not yet available, teams should restrict incoming network access to orchestrator interfaces using strict ingress IP filtering or private management networks. Furthermore, administrators should inspect management server logs and telemetry for anomalous internal function invocations or unexpected changes to downstream Edge configurations.
Read original source