Arista Confirms Active Exploitation of Critical VeloCloud Flaw

Attackers are actively targeting a critical vulnerability in Arista's VeloCloud Orchestrator, affecting certificate-based setups.
Key points
- CVE-2026-93952 is a CVSS 10.0 flaw in VeloCloud Orchestrator that allows unauthenticated remote access to internal functions.
- Only deployments using certificate-based authentication for edge devices are vulnerable; pre-shared key setups are not affected.
- Patches are available for 5.2 and 6.4 release trains, but fixes for 6.1 and 7.0 are still pending as of September 22.
Arista has confirmed that attackers are actively exploiting a critical security flaw in its VeloCloud Orchestrator, the central server that manages edge devices in software-defined wide area networks. The vulnerability, assigned the identifier CVE-2026-93952, carries a maximum severity score of 10.0, indicating that a successful attack can lead to full compromise of the management system and the devices it controls.
The flaw allows remote attackers to access internal functions without needing valid login credentials, provided the orchestrator is configured to use certificate-based authentication for its edge devices. While Arista has released patches for some software versions, others remain vulnerable, and the company has not disclosed how long the attacks have been underway or how widespread they are.
Certificate setups face the risk
Not every VeloCloud deployment is equally exposed. The vulnerability specifically targets systems where edge devices authenticate to the orchestrator using digital certificates rather than simple shared keys. This means organizations using the "Certificate Deactivated" mode, which relies on pre-shared keys, are not affected by this specific flaw. However, Arista has not clarified which specific certificate modes trigger the vulnerability, leaving some uncertainty for administrators.
The attack requires network access to the orchestrator's web interface and the public part of an edge device's authentication certificate. This is a significant change from a previous flaw disclosed in July, which affected all deployments by default and could not be mitigated by configuration. The current threat is more targeted but remains severe due to the lack of authentication requirements for the initial intrusion.
Patches lag for some versions
As of September 22, fixed software is available for the 5.2 and 6.4 release trains, but patches for the 6.1 and 7.0 trains are still pending. Arista has already secured its hosted and dedicated cloud versions, but on-premises users on the unpatched trains are currently exposed. The company states that fixes for all supported versions are in development and will be added to its security advisory once ready.
Until patches can be installed, Arista recommends restricting web interface access to trusted administrative networks and monitoring for unusual outbound traffic. Administrators should also look for specific signs of compromise, such as unexpected files in system directories or unusual headers in web server logs. The Hacker News has reached out to Arista for further comment on the scope of the exploitation.
Indicators of potential compromise
Arista advises checking web access logs for requests containing unusual path structures, encoded characters, or references to internal services. Specific indicators include the presence of files like 'vc-sysmond' in system directories or the 'x-vc-opt' header in nginx logs. If these signs are found, the company recommends preserving the system state and contacting technical support immediately rather than attempting to remediate without evidence preservation.






