New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
A critical vulnerability (CVE-2026-93952) in VeloCloud Orchestrator (VCO) is actively being exploited, allowing remote attackers to gain internal access and compromise Edge devices. While patches are available for supported releases (5.2 and 6.4), unpatched versions remain vulnerable. Arista recommends limiting access to the VCO web interface and monitoring for suspicious activity.
A critical vulnerability, tracked as CVE-2026-93952, exists within VeloCloud Orchestrator (VCO), a server managing Edge devices in VeloCloud SD-WAN deployments. Attackers are currently exploiting this flaw, enabling remote access to internal functions and potentially compromising connected Edge devices. The vulnerability is only present when VCO is configured to authenticate Edges using certificates – specifically in Certificate Acquire and Certificate Required modes.
As of September 22nd, fixes are available for releases 5.2 and 6.4, but not for 6.1 and 7.0. Arista has already patched the Hosted and Dedicated versions of VCO. Notably, a different VCO flaw was exploited in July and did not require any configuration changes to expose the orchestrator.
To mitigate the risk, Arista advises limiting access to the VCO web interface to trusted administrative networks and monitoring for suspicious outbound network traffic. Additionally, monitoring for backdoor daemons and webshells is recommended.
Signs of compromise include specific file locations (e.g., /usr/local/sbin/.vcnode.js, /usr/local/sbin/vc-sysmond, /etc/systemd/system/vc-sysmon.service) and unusual HTTP headers in nginx logs (x-vc-opt). Specific IP addresses (142.93.149[.]77, 104.248.126[.]159) have also been identified as associated with exploitation attempts. If a compromise is suspected, it is crucial to preserve VCO logs and file system timestamps before any remediation steps are taken.
Following an upgrade, incident response should include rotating credentials, reviewing administrator activity, and verifying the state of managed Edge devices. Customers on unsupported release trains should contact Arista's Technical Assistance Center (TAC) for upgrade options.
