Arista Networks has issued a critical security update to address a zero-day vulnerability in its VeloCloud Orchestrator (VCO) platform. The flaw, identified as CVE-2026-93952, is being actively exploited by remote threat actors and affects on-premises deployments of VCO where certificate-based authentication is configured.
The issue lies in an improper input validation weakness that allows attackers to access privileged internal VCO host functionality without requiring privileges on the targeted system or user interaction. This means that even if a network’s security controls are in place, an attacker can still gain unauthorized access to sensitive areas of the VCO platform.
VCO is a cloud-based management tool used by administrators to configure and manage Software-Defined Wide Area Networks (SD-WANs) and associated edge devices. Arista warns that access to the public portion of the VeloCloud Edge authentication certificate is required for an attack, which can be obtained through network access to the VCO web interface.
The good news is that Arista has already patched hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later. However, administrators of on-premises instances running older versions (VCO 6.1.3.7 and below, and VCO 7.0.0.2 and below) need to apply the security patches as soon as possible.
The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog and is requiring federal civilian executive branch agencies to secure their networks by September 25th. This highlights the importance of addressing this vulnerability promptly.
To mitigate the risk, administrators should restrict access to the VCO web interface, review recent administrator activity for unusual changes, and monitor for connections from known malicious IP addresses. Additionally, they should review VCO web access logs for suspicious activity, such as requests containing encoded characters or high request rates.
Arista recommends blocking specific IP addresses (142[.]93.149.77 and 104[.]248.126.159) and reviewing nginx logs for the x-vc-opt HTTP header. Any unexpected outbound HTTP or HTTPS activity originating from the VCO host may also warrant further investigation.
If compromise is suspected, operators should preserve relevant logs and system data before remediation to aid in forensic analysis. Arista encourages customers to contact their Technical Assistance Center (TAC) if they need additional assistance.
This vulnerability is not an isolated incident; Arista has previously patched two other zero-day flaws (CVE-2026-7473 and CVE-2026-16812) that were being actively exploited in attacks against Extensible Operating System (EOS) and on-premises VeloCloud Orchestrator deployments, respectively.
To protect against similar vulnerabilities in the future, it’s essential to maintain a robust security posture, including regular patching, monitoring of system logs, and implementation of access controls. By staying vigilant and proactive, administrators can reduce the risk of successful attacks and ensure the integrity of their networks.
Source: Bleeping Computer — 2026-09-23