VeloCloud Orchestrator flaw under active exploitation lets remote attackers compromise SD-WAN management servers
Arista disclosed on September 22 that attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator, the server that manages Edge devices across a VeloCloud SD-WAN. Tracked as CVE-2026-93952 and rated 10.0, it lets a remote attacker with no login reach internal functions and affect the orchestrator host, but only where Edges authenticate using certificates. A compromised orchestrator exposes the data it manages and can give access to the Edge devices under it. Arista says the flaw was found externally and is known to be actively exploited. Fixed releases exist for the 5.2 and 6.4 trains, with 6.1 and 7.0 still pending.
- Check
- Identify on-premises VeloCloud Orchestrator instances using certificate-based Edge authentication, then apply the fixed 5.2 or 6.4 release and restrict web interface access.
- Affected
- On-premises orchestrators configured for certificate-based Edge authentication let unauthenticated remote attackers reach internal functions, compromise the host, and pivot to managed Edge devices.
- Fix
- Upgrade to fixed 5.2 or 6.4 releases, limit orchestrator web access to trusted networks, and monitor for the July flaw already reported exploited.