New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Summary
A critical flaw in VeloCloud Orchestrator (VCO), tracked as CVE-2026-93952, is being actively exploited by attackers. This vulnerability can allow remote attackers with no login access to gain elevated privileges and impact the VCO host, specifically in certificate-based setups.
IFF Assessment
FOE
This vulnerability allows attackers to gain unauthorized access and control over critical network infrastructure, posing a significant threat to defenders.
Severity
10.0
Critical
Defender Context
This critical vulnerability in VeloCloud Orchestrator requires immediate attention for organizations using certificate-based authentication for their SD-WAN edges. Defenders should prioritize patching or mitigating this flaw to prevent unauthorized access and potential host compromise.