chiprook
← Security
SecuritySeptember 24, 2026, 20:32

Actively exploited VeloCloud Orchestrator flaw patched only in some versions

Arista warned that CVE-2026-93952, a critical CVSS 10.0 flaw in on-prem VeloCloud Orchestrator, is being actively exploited to reach privileged internal functionality. Fixes are available only for versions 5.2.3.16 and 6.4.2.8, leaving other release trains exposed.

Actively exploited VeloCloud Orchestrator flaw patched only in some versions
#Arista#VeloCloud
Read next
Security

Stockton Hid $3.15 Million Surveillance Contract as 'Animal Shelter Study'

Security

Zero-day in Meta's Muse macOS client bypassed security via debug setting

Security

DoJ: Uncle Sam bought forensics software from same Russian op supplying FSB

Security

Ghost Service Accounts Enable M365 Data Theft in Chile