Skip to content
TrustList
News

Arista VeloCloud Orchestrator flaw is exploited, and two release trains have no fix yet

Editorial

By TrustList Editorial

A maximum-severity flaw in self-hosted VeloCloud Orchestrator, the SD-WAN management console, is under attack. Fixes exist for the 5.2 and 6.4 trains only; 6.1 and 7.0 must restrict access and wait.

About Arista VeloCloud Orchestrator flaw is exploited, and two release trains have no fix yet

Arista VeloCloud Orchestrator flaw is exploited, and two release trains have no fix yet

22 September 2026 — Arista has warned that a maximum-severity flaw in self-hosted VeloCloud Orchestrator (VCO), the management console for the VeloCloud SD-WAN service, is being exploited. Security Advisory 0183, published on 22 September 2026 and revised the next day, covers CVE-2026-93952, an input validation flaw rated 10.0 on the CVSS 3.1 scale. CISA added it to the Known Exploited Vulnerabilities catalogue on 22 September with a 25 September deadline for US federal agencies.

What changes

According to Arista, a remote attacker can use the flaw to reach privileged internal functions and affect the VCO host, with no operator login. The attacker needs network access to the VCO web interface, and certificate-based authentication must be configured between VeloCloud Edges and the orchestrator.

Only on-premises VCO is affected. Arista says its Hosted and Dedicated VCO services were also vulnerable but have already been patched, and that VeloCloud Edge and Gateway devices are not affected.

The affected versions are 5.2.3.15 and earlier, 6.1.3.7 and earlier, 6.4.2.7 and earlier, and 7.0.0.2 and earlier. Fixed releases exist for two trains only, 5.2.3.16 and 6.4.2.8. Arista says fixes for the other trains will be added over time, so a customer on 6.1 or 7.0 has, today, no patched version in its own train. One trade report read the fixed versions as applying to hosted deployments; Arista's advisory lists them as the on-premises fixes, and that is what this item follows.

Arista has published signs of compromise: two files, /usr/local/sbin/.vcnode.js and /usr/local/sbin/vc-sysmond, an unusual x-vc-opt header in nginx logs, and two named IP addresses.

Who is affected

Organisations that host their own VCO, and managed service providers and telecoms firms that run VCO for their SD-WAN customers. If you buy SD-WAN as a managed service, the orchestrator may belong to your provider rather than to you, but a compromise there could still let an attacker change your network's configuration.

What to do

  • Find out who runs your orchestrator: Arista, a service provider or your own team.
  • If you run it on 5.2 or 6.4, upgrade to 5.2.3.16 or 6.4.2.8 now.
  • On 6.1 or 7.0, limit the web interface to trusted administration networks, block the listed IP addresses and ask Arista for a fix date or a supported upgrade path.
  • Check each VCO host for the published files and log entries, review administrator activity for unexpected changes and look for unusual outbound traffic.
  • If a provider runs VCO for you, ask for its version, the date it patched and the result of its compromise checks, in writing.

Sources