CVSS 10.0 VeloCloud Orchestrator flaw actively exploited
Arista said attackers are actively exploiting CVE-2026-93952 in on-premises VeloCloud Orchestrator (VCO), the server managing Edge devices in a VeloCloud SD-WAN. An unauthenticated remote attacker can reach internal functions and affect the VCO host; only setups using certificate-based Edge authentication are affected.
- CVE-2026-93952 carries a maximum CVSS score of 10.0
- No login is required to exploit the flaw
- Only certificate-based Edge authentication setups are affected
- Arista reported active exploitation on September 22
Read next
Security