Arista VeloCloud Orchestrator Flaw Under Active Attack

Arista VeloCloud Orchestrator CVE-2026-93952 SD-WAN management vulnerability under active exploitation

A critical hole in an SD-WAN management hub has already crossed from advisory to real-world attack: Arista has confirmed exploitation of a VeloCloud Orchestrator vulnerability that, under a certain configuration, lets a remote attacker with no account reach privileged internal functions of the management server.

On September 22, Arista warned of active exploitation of CVE-2026-93952. The company rated the flaw 10.0 on CVSS 3.1 and 9.5 on CVSS 4.0. The cause is improper input validation, classified as CWE-20. Arista laid out the full details in its official security advisory.

What VeloCloud Orchestrator Manages

VeloCloud Orchestrator, or VCO, serves as the central management system for VeloCloud Edge devices within a software-defined wide-area network, or SD-WAN. Through the orchestrator, administrators configure branch offices and edge nodes, so a successful breach could affect the server itself, the data it stores, its configurations, and the devices under its management.

When the Orchestrator Is Exposed

The attack does not work against every VCO installation. The risk arises when Edge devices authenticate to the orchestrator via certificates. The attacker needs network access to the VCO web interface and the public portion of a VeloCloud Edge authentication certificate. Credentials for a VCO tenant or operator are not required for exploitation.

What a Successful Breach Enables

Arista has not disclosed when the attacks began, how many organizations were affected, or who stands behind the campaign. The vendor confirmed only the fact of real-world exploitation. Once compromised, an attacker can undermine the confidentiality, integrity, and availability of the VCO and the data it manages, and a hijacked orchestrator can open a path to the connected VeloCloud Edge devices.

Affected Versions and Fixes

Vulnerable are on-premises VCO installations in the 5.2.x branch up to and including 5.2.3.15, 6.1.x up to 6.1.3.7, 6.4.x up to 6.4.2.7, and 7.0.x up to 7.0.0.2. The cloud-based Hosted and Dedicated versions were also affected, but Arista has already fixed them on its side. For on-premises installations, ready fixes do not yet exist across all supported branches.

A fix has been released for VCO 5.2.3.16 and 6.4.2.8. At the time the advisory was published, fixed versions for the 6.1 and 7.0 branches had not yet been named. Arista promised to add new builds as they are released. Until an update is available, the company advises allowing access to the VCO web interface only from trusted administrative networks.

Indicators of Compromise

To help find traces of an attack, Arista provided specific indicators. Administrators are advised to check the files /usr/local/sbin/.vcnode.js, /usr/local/sbin/vc-sysmond, and /etc/systemd/system/vc-sysmon.service, the x-vc-opt header in nginx logs, and connections to the addresses 142.93.149.77 and 104.248.126.159.

No single universal sign of compromise exists. Suspicion should be raised by unusual paths and encoded characters in requests to the VCO, unexpected outbound HTTP or HTTPS traffic, file creation, command execution, database dumps, and configuration changes made without corresponding administrator action.

Part of a Pattern in SD-WAN Attacks

The incident continues a series of attacks on SD-WAN management components. In the spring, attackers had already seized Cisco controllers through another vulnerability rated 10 out of 10. Arista advises that, after updating, administrators change credentials, check the status of Edge devices, and, if signs of compromise appear, restore the orchestrator from a trusted source.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply