VYPR
advisoryPublished Sep 22, 2026· 1 source

Critical CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited

A critical vulnerability in Arista's VeloCloud Orchestrator (VCO), rated CVSS 10.0, is being actively exploited by attackers who can gain internal privileges without authentication.

Arista has disclosed a critical vulnerability, tracked as CVE-2026-93952, affecting on-premises VeloCloud Orchestrator (VCO) deployments that use certificate-based authentication for their Edge devices. This flaw allows remote attackers, even without any login credentials, to potentially gain internal privileges and compromise the VCO host. The vulnerability carries a severe CVSS 3.1 score of 10.0, indicating a high potential for impact, including the compromise of the orchestrator, the data it manages, and potentially the Edge devices it controls.

The vulnerability specifically targets VCO instances configured for certificate-based authentication between VeloCloud Edges and the orchestrator. While Arista did not specify which certificate modes are affected, it noted that attackers require network access to the VCO web interface and the public part of an Edge's authentication certificate. This contrasts with a previously disclosed VCO flaw in July (CVE-2026-16812), which was exploitable by default without specific configuration requirements.

Arista confirmed that the flaw was discovered externally and is known to be actively exploited in the wild. However, the company has not yet disclosed the timeline of these attacks or their extent. The Hacker News has reached out to Arista for further comment on the ongoing exploitation.

As of September 22, Arista has released patches for the 5.2 and 6.4 release trains, with fixed versions being 5.2.3.16 and later, and 6.4.2.8 and later, respectively. The Hosted and Dedicated versions of VCO have also been patched. However, fixes for the 6.1 and 7.0 release trains are still pending. For customers on unsupported release trains, Arista advises contacting their Technical Assistance Center (TAC) to discuss upgrade options.

For organizations unable to upgrade immediately, Arista recommends several mitigation strategies. These include limiting access to the VCO web interface to trusted administrative networks, monitoring the VCO for suspicious inbound and outbound network traffic, and blocking non-essential outbound ports. Additionally, security teams should monitor for unexpected administrator activity, backdoor daemons, and webshells.

Arista has also provided specific indicators of compromise (IoCs) to help detect exploitation. These include unusual file paths like /usr/local/sbin/.vcnode.js and /usr/local/sbin/vc-sysmond, specific MD5 hashes for vc-sysmond, and suspicious entries in Nginx logs such as the x-vc-opt HTTP header. Known malicious IP addresses associated with the attacks are 142.93.149[.]77 and 104.248.126[.]159.

In the event of a suspected compromise, Arista urges customers to preserve the state of the VCO, including logs and file system timestamps, before applying any fixes. Post-incident response recommendations include rotating credentials, reviewing administrator actions, checking the security of managed Edge devices, and potentially restoring the orchestrator from trusted backups. The company emphasizes that a thorough incident response is crucial to fully remediate the impact of this critical vulnerability.

Synthesized by Vypr AI