ZoomEye: 6,050 VeloCloud Orchestrator systems exposed online amid CVE-2026-93952
ZoomEye found 6,050 internet-reachable systems matching the VeloCloud Orchestrator fingerprint as Arista confirms active exploitation of CVE-2026-93952, rated CVSS 10.0. Fixes are available in builds 5.2.3.16 and 6.4.2.8.
- Query http.body="VeloCloud" returned 6,050 systems; http.header returned 5,037
- vul.cve="CVE-2026-93952" filter returned 0 as the flaw is not yet indexed
- Vulnerable builds: 5.2.3.15 and earlier, 6.1.3.7, 6.4.2.7, 7.0.0.2 and below
- Defenders should restrict the VCO web interface to trusted subnets
Read next
Security