Arista Warns of Active Exploitation of CVE 2026 93952 in VeloCloud Orchestrator

Published:

Arista has disclosed that attackers are actively exploiting a newly identified vulnerability in on premises VeloCloud Orchestrator (VCO), the centralized server responsible for managing Edge devices in VeloCloud SD WAN environments. Tracked as CVE-2026-93952, the flaw has received the maximum CVSS 3.1 severity score of 10.0 because of its potential impact on affected deployments. According to Arista, the vulnerability could allow a remote attacker without login credentials to gain privileged access to internal functions and compromise the VCO host. The company confirmed that only deployments configured to authenticate VeloCloud Edge devices using certificates are affected. Arista announced the issue on September 22 and has stated that the vulnerability is already being actively exploited in the wild. Although the company did not disclose when the activity began or how widespread it has become, it warned that organizations using impacted configurations should act quickly. 

Security updates are currently available for the 5.2 and 6.4 release trains, while fixes for the 6.1 and 7.0 release trains are still under development. Arista also confirmed that its Hosted and Dedicated VeloCloud Orchestrator services have already been patched. The newly disclosed vulnerability affects software releases that had previously addressed another VCO security issue, CVE-2026-16812, which Arista reported as being exploited earlier this year. While that earlier vulnerability affected VCO deployments regardless of configuration, the latest flaw specifically targets orchestrators that use certificate based authentication between Edge devices and the orchestrator. VeloCloud Edge devices support three authentication methods, including Certificate Deactivated mode, which relies on a pre shared key, and Certificate Acquire and Certificate Required modes, both of which use certificates issued by the orchestrator. Arista noted that orchestrators configured for certificate based authentication are exposed when attackers can access the VCO web interface and obtain the public portion of an Edge authentication certificate. A successful compromise could impact the orchestrator itself, the sensitive information it manages, and potentially the connected Edge devices under its administration.

For organizations that are unable to immediately install the available updates, Arista has recommended several temporary mitigation measures to reduce exposure. These include restricting access to the VCO web interface so that it is only reachable from trusted administrative networks, monitoring access attempts originating from known malicious IP addresses, reviewing unexpected outbound network activity from the VCO host, limiting unnecessary outbound network ports, and checking systems for unauthorized services or suspicious webshell activity. Administrators are also advised to review recent management actions for unexpected configuration changes. The company said supported release trains will receive fixes as they become available, while customers running unsupported software versions should contact Arista Technical Assistance Center to discuss upgrade options. This guidance is intended to reduce operational risk until organizations can deploy permanent software updates.

Arista also shared several indicators that may help administrators identify suspicious activity associated with the vulnerability, while noting that no single indicator alone confirms a successful compromise. Security teams are encouraged to inspect VCO web access logs for unusual URL style requests, encoded characters, references to local or internal services, and unusually high request volumes. Other indicators include the presence of unexpected files such as /usr/local/sbin/.vcnode.js, /usr/local/sbin/vc-sysmond, and /etc/systemd/system/vc-sysmon.service, along with the MD5 hash dc78e206eaeadec59fc5801fe4556bd0 for the vc-sysmond file. Administrators should also watch for the x-vc-opt HTTP header in nginx logs and network activity involving the IP addresses 142.93.149.77 and 104.248.126.159. If any of these indicators are discovered, Arista recommends preserving the current state of the orchestrator, collecting web access, backend application, database, and system logs where practical, and contacting Arista Technical Assistance Center or the organization’s Arista account team before proceeding. Following the installation of security updates, organizations are also advised to perform incident response activities, including credential rotation, administrator activity reviews, verification of managed Edge devices, and restoration or replacement of the orchestrator from trusted sources if necessary.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img