On-prem VeloCloud Orchestrator under attack, only some versions patched

Summary

Arista has issued a security advisory for a critical vulnerability in its on-premises VeloCloud Orchestrator (VCO) deployments. The flaw, tracked as CVE-2026-93952, allows remote attackers to access privileged internal functionality and impact the VSO host, and is known to be actively exploited. Patches are available for some versions, but unpatched deployments remain exposed.

IFF Assessment

FOE

The article describes an actively exploited critical vulnerability, which is bad news for defenders as it poses a significant risk to their infrastructure.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 25, 2026. Known ransomware use: Unknown.

Defender Context

Defenders need to prioritize patching their on-premises VeloCloud Orchestrator deployments immediately, especially given the critical CVSS score and active exploitation. For unpatched systems, compensating controls should be implemented, and organizations should be prepared to investigate potential compromises by preserving relevant logs and system data.

Read Full Story →