Actively exploited VeloCloud Orchestrator flaw patched only in some versions
Arista warned that CVE-2026-93952, a critical CVSS 10.0 flaw in on-prem VeloCloud Orchestrator, is being actively exploited to reach privileged internal functionality. Fixes are available only for versions 5.2.3.16 and 6.4.2.8, leaving other release trains exposed.
- CVE-2026-93952 carries a maximum CVSS score of 10.0
- Affected: 5.2.3.15, 6.1.3.7, 6.4.2.7, 7.0.0.2 and earlier
- Patches released only for 5.2.3 and 6.4.2 trains
- Exploitation requires Edge certificate auth to VCO
Read next
Security