news.mlab.sh
Back to the feed
vulnerability

Arista Urges Immediate Patching of Exploited VCO Zero-Day

CriticalCVSS 10.0
Summary

Arista Networks has issued a critical patch for a zero-day vulnerability in its VeloCloud Orchestrator (VCO) that’s currently being actively exploited. The flaw, CVE-2026-93952, allows remote attackers to access privileged functionality if certificate-based authentication is enabled. Federal agencies were given a short window to address the issue, and Arista urges all users to update immediately to mitigate the risk.

Arista Networks has released a critical patch for a zero-day vulnerability affecting its VeloCloud Orchestrator (VCO) management tool. The vulnerability, identified as CVE-2026-93952, has been confirmed to be actively exploited in the wild. VeloCloud Orchestrator is used to configure, monitor, and orchestrate edge devices, policies, and traffic within Arista’s VeloCloud SD-WAN solutions.

The issue stems from an improper input validation flaw. Successful exploitation could compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. The vulnerability is only exploitable if certificate-based authentication from the VeloCloud Edge to VCO is enabled, requiring access to the public portion of the VeloCloud Edge authentication certificate.

Arista notes that deployments with limited access to the VCO web interface are at a lower risk, but strongly recommends updating to a fixed release. The company advises administrators to review VCO web access logs, backend application logs, and system logs for any suspicious activity.

This vulnerability has been added to the CISA’s Known Exploited Vulnerabilities (KEV) list, and federal agencies were given three days to patch it. Related vulnerabilities, including a zero-day in F5 BIG-IP APM and a zero-day in Check Point’s Management Server, have also been reported.

Read the full article at SecurityWeek