Arista Networks released urgent fixes for CVE-2026-93952, a CVSS 10.0 improper-input-validation flaw in on-premises VeloCloud Orchestrator (VCO) that has been exploited as a zero-day. An attacker with network access to the VCO web interface and the public portion of a VeloCloud Edge authentication certificate can reach privileged internal functionality without tenant or operator credentials, potentially compromising the confidentiality, integrity, and availability of the orchestrator and managed data. Affected versions include VCO 5.2.0–5.2.3.15, 6.1.0–6.1.3.7, 6.4.0–6.4.2.7, and 7.0.0–7.0.0.2; fixes are available in 5.2.3.16 and 6.4.2.8, with other release-train patches pending.
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, requiring U.S. federal agencies to remediate within three days. Administrators should apply Arista updates immediately and investigate VCO hosts for published indicators, including malicious files, a vc-sysmond implant, unauthorized systemd services, and suspicious source IPs in nginx logs. Rapid7 has proposed detection-only Metasploit modules to fingerprint potentially affected VCO interfaces and conduct local read-only IOC checks; the project cautions that a favicon can identify VCO but cannot reliably establish its version remotely, and exploitation also requires Edge-to-VCO certificate material.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-947 for CVE-2026-93952 in Arista VeloCloud Orchestrator On-Prem, reporting active exploitation. The notice identified affected releases across the 5.2, 6.1, 6.4, and 7.0 branches and advised administrators to apply relevant updates.
A draft Metasploit pull request proposed a detection-only HTTP scanner to fingerprint VeloCloud Orchestrator and assess affected version ranges, plus a read-only Linux post module to search for published exploitation indicators. The IOC module checks for malicious files, a vc-sysmond implant hash, the vc-sysmon.service unit, and attacker IP addresses in nginx logs.
CISA added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog. Under BOD 26-04 guidance, U.S. federal agencies were given three days to remediate the flaw.
Arista disclosed CVE-2026-93952 as a CVSS 10.0 improper-input-validation flaw in on-premises VeloCloud Orchestrator that can permit access to privileged internal functionality when Edge-to-VCO certificate authentication is configured. It released fixed versions 5.2.3.16 and 6.4.2.8, while patches for other release trains remained pending.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcegithub.com
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.