CVE-2026-93952 is a critical improper input validation vulnerability in on-prem Arista VeloCloud Orchestrator that lets an unauthenticated remote attacker reach privileged internal functionality and compromise the orchestrator host.
What Is It
The flaw is tracked as CWE-20 (Improper Input Validation) in Arista's VeloCloud Orchestrator (VCO) on-prem product. A remote attacker may use it to access privileged internal functionality and impact the VCO host itself. Successful exploitation may compromise the confidentiality, integrity, and availability of both the orchestrator and the data it manages.
Arista PSIRT scored the issue CVSS v3.1 10.0 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network-reachable, low complexity, no privileges, no user interaction, and a changed scope. A CVSS v4.0 score of 9.5 (CRITICAL) was also assigned.
Why It Matters
CISA added CVE-2026-93952 to the Known Exploited Vulnerabilities catalog on 2026-09-22, the same day the CVE was published, confirming active exploitation in the wild. CISA's SSVC decision data marks the vulnerability as exploitation active, automatable: yes, and technical impact total. Known ransomware campaign use is listed as Unknown.
The KEV entry also flags forensic triage as required, and the remediation deadline was set to 2026-09-25; three days after the catalog addition.
What's Vulnerable
Per Arista's affected-product data, VeloCloud Orchestrator On-Prem is affected in these version ranges:
- 5.2.0 through 5.2.3.15
- 6.1.0 through 6.1.3.7
- 6.4.0 through 6.4.2.7
- 7.0.0 through 7.0.0.2
All other versions default to unaffected. Hosted VCO deployments, including Dedicated, were impacted but have already been patched by Arista.
Patch Status
Hosted and Dedicated VCO instances are already patched. On-prem operators must act themselves.
CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines. Due date: 2026-09-25.
Sources
- Arista Security Advisory 0183; https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93952
- NVD, CVE-2026-93952, https://nvd.nist.gov/vuln/detail/CVE-2026-93952
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements; https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk