chiprook
← Security
SecuritySeptember 22, 2026, 19:29

CVSS 10.0 VeloCloud Orchestrator flaw actively exploited

Arista said attackers are actively exploiting CVE-2026-93952 in on-premises VeloCloud Orchestrator (VCO), the server managing Edge devices in a VeloCloud SD-WAN. An unauthenticated remote attacker can reach internal functions and affect the VCO host; only setups using certificate-based Edge authentication are affected.

CVSS 10.0 VeloCloud Orchestrator flaw actively exploited
#Arista#VeloCloud
Read next
Security

Hacktron used zero-day to reach OpenAI's GitHub, sparking disclosure debate

Security

Microsoft disrupts EvilTokens phishing service that hit 12,000 accounts

Security

NCSC: agentic AI cyber defense faces organizational, not technical, barriers

Security

Palo Alto Networks launches always-on AI security testing on Claude Mythos and GPT-5.6-Cyber