
Arista has disclosed CVE-2026-93952, a second CVSS 10.0 flaw in its VeloCloud Orchestrator (VCO) — the management server that oversees all Edge devices in a VeloCloud SD-WAN deployment. Unlike the July zero-day (CVE-2026-16812), which exposed every VCO by default, this new flaw only affects orchestrators that use certificate-based Edge authentication. Arista confirmed the vulnerability “was discovered externally and is known to be actively exploited.”
A remote attacker with no credentials can exploit the flaw to access internal VCO functions. If successful, the attacker can compromise the orchestrator itself, the data it manages, and potentially reach every Edge device the VCO controls. Fixed releases are out for the 5.2 and 6.4 trains; deployments running 6.1 (through 6.1.3.7) or 7.0 (through 7.0.0.2) have no patch yet. Arista’s Hosted and Dedicated cloud versions are already patched. Known indicators of compromise include the presence of /usr/local/sbin/.vcnode.js or /usr/local/sbin/vc-sysmond (MD5: dc78e206eaeadec59fc5801fe4556bd0) on the VCO host, and outbound connections to 142.93.149[.]77 or 104.248.126[.]159.
How to check if you’re affected
Affected versions are those running VeloCloud Orchestrator with certificate-based Edge authentication enabled — specifically any VCO in Certificate Acquire or Certificate Required mode. Check your release: 5.2.3.15 and earlier, 6.1.3.7 and earlier, 6.4.2.7 and earlier, and 7.0.0.2 and earlier are all vulnerable. If a patch is not yet available for your train, Arista recommends restricting VCO web interface access to trusted administrative networks, monitoring for the IoC files and IPs listed above, and watching for unexpected outbound traffic or new webshells.
