Arista Fixes Critical Zero-Day in VeloCloud Orchestrator
Arista Networks has issued security updates to address a zero-day vulnerability being actively exploited in VeloCloud Orchestrator (VCO) on-premises deployments.
Overview of the Vulnerability
The flaw, tracked as CVE-2026-93952, arises from a flaw in input validation and impacts VCO systems configured with certificate-based authentication between VeloCloud Edge devices and the VCO platform. Attackers can leverage this weakness to gain access to privileged internal functions of the VCO host through low-complexity remote attacks, without requiring system-level privileges or user interaction.
Patches and Affected Versions
Arista has already deployed patches for hosted VCO instances running versions 5.2.3.16 and later, as well as 6.4.2.8 and later. Patches for older versions, including 6.1.3.7 and below, and 7.0.0.2 and below, are scheduled for release.
CISA Mandate and Security Recommendations
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included CVE-2026-93952 in its Known Exploited Vulnerabilities catalog and mandated that U.S. federal civilian executive branch agencies implement protective measures by September 25. Security teams are advised to restrict access to the VCO web interface to administrative networks, audit recent administrator activity for anomalies, and monitor for connections from malicious IP addresses.
Indicators of Compromise
Specific indicators of compromise include requests with encoded characters, unusual URL components, references to internal services, and high-volume traffic. Administrators should block the IP addresses 142[.]93.149.77 and 104[.]248.126.159 and inspect nginx logs for the x-vc-opt HTTP header. Unexpected outbound HTTP or HTTPS traffic from the VCO host may also signal compromise.
Recent Zero-Day Vulnerabilities
This marks the third zero-day vulnerability addressed by Arista this year, following patches for CVE-2026-7473 in May and CVE-2026-16812 in July, both of which were linked to active exploitation in attacks targeting Extensible Operating System (EOS) and on-premises VeloCloud Orchestrator deployments.
Conclusion
Arista Networks, a Fortune 500 company with over 10,000 global customers, continues to address critical security risks in its product ecosystem. Customers are encouraged to contact Arista Networks’ Technical Assistance Center for support.
“The vulnerability was identified externally and confirmed to be in active use by threat actors.”
