Arista Networks has just released security patches for a critical vulnerability that is being actively exploited by remote threat actors. The flaw affects VeloCloud Orchestrator (VCO) On-Prem deployments, which are used to manage Software-Defined Wide Area Networks (SD-WANs). This means that thousands of organizations worldwide are at risk of being compromised.
The vulnerability, tracked as CVE-2026-93952, stems from an improper input validation weakness in the way VCO handles certificate-based authentication. In simple terms, this means that attackers can exploit the flaw to gain access to sensitive internal functionality without needing any special privileges or user interaction. The attack complexity is relatively low, making it a significant threat.
Arista Networks has already patched hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later. However, the company will also release security patches for earlier versions of VCO, including 6.1.3.7 and below, and 7.0.0.2 and below. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to secure their networks by Friday.
To mitigate the risk, administrators should immediately restrict access to the VCO web interface to administrative networks and review recent administrator activity for unusual changes. They should also monitor for connections from known malicious IP addresses and review VCO web access logs for suspicious activity such as requests containing encoded characters or high request rates. Arista Networks has provided a list of indicators of compromise, which includes blocking specific IP addresses and reviewing nginx logs.
If an organization suspects that they have been compromised, they should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible. In this case, it’s essential to contact the Arista Networks Technical Assistance Center (TAC) for additional assistance.
This is not the first time Arista Networks has patched a zero-day flaw that was being actively exploited in attacks. Since the start of the year, the company has patched two other vulnerabilities, including CVE-2026-7473 and CVE-2026-16812, which affected Extensible Operating System (EOS) and on-premises VeloCloud Orchestrator deployments, respectively.
Arista Networks is a Fortune 500 company with over 10,000 customers worldwide. This vulnerability highlights the importance of keeping software up-to-date, especially for critical systems like SD-WAN management platforms. It also underscores the need for organizations to have robust security measures in place to detect and respond to potential attacks.
Source: Bleeping Computer — 2026-09-23