Arista Says a VeloCloud Orchestrator Bug Is Already Being Exploited

A remote attacker with no login can reach privileged functions on the server that runs an entire SD-WAN network. On-prem customers using certificate authentication need to act now.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Full-frame edge-to-edge photoreal shot of a dimly lit enterprise server rack with a single network orchestrator appliance glowing amber, blurred fiber patch cab
Share

Key points

  • Arista disclosed CVE-2026-93952 in VeloCloud Orchestrator on 22 September 2026, a critical flaw that lets a remote attacker with no login reach privileged internal functions on the server.
  • Attackers are already using the flaw against on-premises orchestrators, according to Arista's advisory.
  • Only orchestrators configured to authenticate their Edge devices using certificates are exposed.
  • Hosted and Dedicated cloud versions have already been patched by Arista; on-prem customers must patch themselves.
  • Threat Vectr's own leak-site tracking shows a rising share of ransomware crews listing victims whose initial entry was through network management gear, making an unpatched orchestrator an attractive target.

Arista Networks is telling customers to patch VeloCloud Orchestrator immediately. The company disclosed the bug, CVE-2026-93952, on 22 September 2026 and confirmed attackers are already exploiting it.

The orchestrator is the brain of a VeloCloud SD-WAN, software companies use to connect their branch offices and cloud services into one managed network. Whoever controls the orchestrator controls every site it manages.

What is the flaw?

A remote attacker with no account on the system can reach privileged internal functions on the orchestrator, according to the NVD entry for CVE-2026-93952. Arista's writeup says a successful attack can affect the orchestrator host and any data it manages. The CVSS score is 10.0, the top of the severity scale.

In plain terms: someone on the internet, with no password, can talk to parts of the server that are supposed to be off-limits and take it over from there.

Who is actually at risk?

On-premises customers who authenticate their Edge devices with certificates. That's the specific configuration Arista flagged in its 22 September advisory, first reported by The Hacker News. Edge devices are the small appliances in each branch office that connect back to the orchestrator. Sites that authenticate those Edges with certificates expose the vulnerable code path.

Hosted and Dedicated cloud versions have already been patched by Arista, so customers on those tiers don't need to act. On-prem operators do.

What should network teams do now?

Patch the orchestrator, then check whether anyone got there first.

Detail What Arista says
CVE CVE-2026-93952
CVSS 10.0 (critical)
Disclosed 22 September 2026
Affected On-prem VCO with certificate-based Edge auth
Already fixed Hosted and Dedicated VCO
Exploited in the wild Yes

Because the flaw needs no authentication and hands over privileged functionality, log review should assume the worst: unexpected admin actions, new user accounts, changes to Edge policies, outbound connections from the orchestrator host that don't match normal management traffic. If the orchestrator was internet-reachable and unpatched at any point after 22 September, treat it as potentially compromised until logs prove otherwise.

Should you worry about the timing?

Yes. Management planes are the softest target in most enterprise networks: they sit above the firewalls and hold credentials for every site. A pre-auth bug on one of them is exactly what ransomware affiliates pay for. We covered a near-identical pattern on 17 September with the Cisco Secure Email Gateway zero-day, where no login was required and exploitation was already under way before most teams had read the advisory. The window between disclosure and mass scanning on flaws like this has been days, not weeks.

On-prem VeloCloud customers shouldn't wait for the weekend.

© 2026 Threat Vectr