Arista Urges Immediate Patch for Exploited VCO Zero-Day Vulnerability

www.news4hackers.com-arista-urges-immediate-patch-for-exploited-vco-zero-day-vulnerability-arista-urges-immediate-patch-for-exploited-vco-zero-day-vulnerability

Arista has issued urgent advisories for a critical vulnerability impacting on-premises VeloCloud Orchestrator (VCO) deployments, which has been actively exploited in the wild.

Critical Vulnerability Details

The flaw, designated CVE-2026-93952 with a CVSS score of 10, stems from a flaw in input validation processes that could enable remote adversaries to access privileged internal functions.

Affected Systems and Patches

This vulnerability affects the centralized management platform used for configuring and monitoring edge devices, policies, and traffic within Arista VeloCloud SD-WAN environments. Patches have been released for versions 5.2.3.16 and 6.4.2.8 within the 5.2.x and 6.1.x release trains, respectively.

Exploitation Conditions

The security flaw was identified externally and confirmed to be in active exploitation. Attackers require access to the public portion of the authentication certificate and network access to the VCO web interface. Notably, tenant or operator credentials are not necessary for exploitation.

CISA KEV Listing and Recommendations

The vulnerability was added to CISA’s Known Exploited Vulnerabilities (KEV) list on Tuesday, prompting federal agencies to address the issue within three days per BOD 26-04 guidelines. Arista emphasized that systems restricting access to the VCO web interface face reduced risk but strongly recommend applying the latest patches.

Conclusion

Organizations utilizing VCO must prioritize updates to mitigate potential risks associated with this high-severity vulnerability. No definitive indicators of compromise (IoCs) have been identified, though administrators are advised to scrutinize web access logs, backend application logs, and system logs for anomalous activity.


Blog Image

About Author

en_USEnglish