CVE-2026-93952: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
Summary
Arista VeloCloud Orchestrator (VCO) on-prem has an improper input validation vulnerability allowing remote attackers to access privileged functionality. Successful exploitation could compromise the confidentiality, integrity, and availability of the orchestrator and its data.
IFF Assessment
This vulnerability allows for unauthorized access to privileged functionality, potentially leading to a compromise of the orchestrator and its data.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 25, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability in Arista VeloCloud Orchestrator presents a significant risk for organizations relying on this platform. Defenders should prioritize applying vendor-provided mitigations and adhere to CISA's guidance on prioritizing security updates based on risk. Monitoring for any signs of exploitation or unauthorized access on affected orchestrators is crucial.