Cybersecurity

Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
0 0
XWhatsAppTelegramLinkedIn

Arista Networks published Security Advisory 0183 on 22 September 2026 for CVE-2026-93952, a flaw in on-premises VeloCloud Orchestrator (VCO), the console enterprises use to run their SD-WAN networks. Arista scores it 10.0 on CVSSv3.1 — the maximum possible — and states plainly: "This issue was discovered externally and is known to be actively exploited." The same day, the US Cybersecurity and Infrastructure Security Agency added the CVE to its Known Exploited Vulnerabilities catalog as one of four entries, setting a federal remediation deadline of 25 September.

The flaw is improper input validation (CWE-20). According to Arista's advisory, a VCO is exposed if certificate-based authentication from VeloCloud Edge appliances to the orchestrator is configured. An attacker needs network access to the VCO web interface and the public portion of an Edge authentication certificate — nothing more. "VCO tenant or operator credentials are not required for this exposure," the advisory says. That combination of remote access, no authentication and a scope change across the host is what produces the perfect score; on the newer CVSSv4.0 scale Arista rates it 9.5.

Affected builds are 5.2.3.15 and below in the 5.2.x train, 6.1.3.7 and below in 6.1.x, 6.4.2.7 and below in 6.4.x, and 7.0.0.2 and below in 7.0.x. Fixes exist so far only in VCO 5.2.3.16 and 6.4.2.8; Arista says patches for the remaining trains "are coming out" and will be added to the advisory when ready, which leaves 6.1.x and 7.0.x operators without a fixed release as of the advisory's 23 September revision. Hosted and Dedicated VCO instances were affected but have already been patched by Arista. Arista's EOS switches, CloudVision, VeloCloud Edge and VeloCloud Gateway are listed as not affected.

For network teams the stakes go beyond one server: Arista warns that compromising the orchestrator "may allow attackers access to the VeloCloud Edge devices as well," and recommends credential rotation, review of administrator activity and rebuilding affected orchestrators from trusted sources. The advisory publishes unusually specific indicators of compromise — the files /usr/local/sbin/.vcnode.js and /usr/local/sbin/vc-sysmond (MD5 dc78e206eaeadec59fc5801fe4556bd0), a service unit at /etc/systemd/system/vc-sysmon.service, an x-vc-opt header in nginx logs, and inbound connections from 142.93.149.77 and 104.248.126.159.

What is still missing is scale. Arista has not said how many on-premises orchestrators were reached, when exploitation started, or who is behind it, and CISA's entry names no threat actor. Until a fixed build exists for their train, Arista tells operators to restrict the VCO web interface to trusted administrative networks, watch for unexpected outbound traffic from the VCO host, and preserve web, application and database logs before any rebuild. CISA's listing also falls under Binding Operational Directive 26-04, which adds forensic triage requirements for federal agencies alongside the 25 September patch date.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.