Cyber & AI intelligence
Wasteland.
Briefs indexed2807
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-93952 2026-09-22

Arista VeloCloud Orchestrator Hit With CVSS 10.0 Input Validation Flaw

"CVE-2026-93952 is a critical improper input validation vulnerability in on-prem Arista VeloCloud Orchestrator that lets an unauthenticated remote attacker reach privileged internal functionality and compromise the…"

CVE-2026-93952 is a critical improper input validation vulnerability in on-prem Arista VeloCloud Orchestrator that lets an unauthenticated remote attacker reach privileged internal functionality and compromise the orchestrator host.

What Is It

The flaw is tracked as CWE-20 (Improper Input Validation) in Arista's VeloCloud Orchestrator (VCO) on-prem product. A remote attacker may use it to access privileged internal functionality and impact the VCO host itself. Successful exploitation may compromise the confidentiality, integrity, and availability of both the orchestrator and the data it manages.

Arista PSIRT scored the issue CVSS v3.1 10.0 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network-reachable, low complexity, no privileges, no user interaction, and a changed scope. A CVSS v4.0 score of 9.5 (CRITICAL) was also assigned.

Why It Matters

CISA added CVE-2026-93952 to the Known Exploited Vulnerabilities catalog on 2026-09-22, the same day the CVE was published, confirming active exploitation in the wild. CISA's SSVC decision data marks the vulnerability as exploitation active, automatable: yes, and technical impact total. Known ransomware campaign use is listed as Unknown.

The KEV entry also flags forensic triage as required, and the remediation deadline was set to 2026-09-25; three days after the catalog addition.

What's Vulnerable

Per Arista's affected-product data, VeloCloud Orchestrator On-Prem is affected in these version ranges:

All other versions default to unaffected. Hosted VCO deployments, including Dedicated, were impacted but have already been patched by Arista.

Patch Status

Hosted and Dedicated VCO instances are already patched. On-prem operators must act themselves.

CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines. Due date: 2026-09-25.

Sources