ZeroDayAlert

CVE-2026-93952: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Arista VeloCloud Orchestrator Added to KEV 2026-09-22 Federal due 2026-09-25 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

This vulnerability affects Arista VeloCloud Orchestrator (VCO) deployed on-premises. The flaw is an improper input validation issue that can permit remote, unauthenticated access to privileged functions within the orchestrator application and the underlying host system. The record does not specify which versions of VCO are vulnerable, nor does it indicate whether the cloud-hosted variant is affected.

How to check whether this touches you

  • Search your asset inventory for any instance of "VeloCloud Orchestrator" or "VCO" labelled as on-premises or self-hosted deployment.
  • Confirm whether each VCO instance is reachable over the network from outside your organisation (via network segmentation maps, firewall rules, or direct probing of management interfaces).
  • Obtain the running software version from the VCO admin console or API; consult Arista's advisory to determine which versions contain the flaw, as version ranges are not specified in this record.
  • If you cannot establish the exact version, treat the instance as potentially vulnerable unless Arista explicitly confirms otherwise in their guidance.

What to do

  1. Immediately: Locate Arista's official security advisory for CVE-2026-93952 and confirm the affected version range and available remediation (patch, configuration change, or workaround).
  2. In parallel: Isolate each affected VCO instance from external network access by restricting inbound routes to trusted administrative clients only, via firewall or network segmentation.
  3. Before patching: Log all access to the VCO management interface, including failed authentication attempts and any API calls, for the period before you discovered and remediated this issue.
  4. Escalate immediately: If your VCO instance is internet-facing, has no patch available, or cannot be isolated, escalate to senior infrastructure and security leadership to evaluate whether discontinuation of the service is necessary under CISA BOD 26-04 guidance.
  5. Apply remediation: Follow Arista's patching instructions and verify successful application in a test environment before rolling out to production.

If you find you were exposed

Check your access logs and network telemetry for the period from when this vulnerability was introduced (unknown from this record) back as far as your log retention allows. Look for any unauthenticated connections to the VCO management port, unusual API calls, or privilege escalation attempts originating from outside your network. If exploitation did occur, you must assume that the confidentiality, integrity and availability of the orchestrator itself and any data it manages may be compromised, and engage incident response and forensics accordingly.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-93952 is being exploited. It cannot tell you whether VeloCloud Orchestrator is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →