← All articles

VeloCloud Orchestrator flaw under active exploitation lets remote attackers compromise SD-WAN management servers

Arista disclosed on September 22 that attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator, the server that manages Edge devices across a VeloCloud SD-WAN. Tracked as CVE-2026-93952 and rated 10.0, it lets a remote attacker with no login reach internal functions and affect the orchestrator host, but only where Edges authenticate using certificates. A compromised orchestrator exposes the data it manages and can give access to the Edge devices under it. Arista says the flaw was found externally and is known to be actively exploited. Fixed releases exist for the 5.2 and 6.4 trains, with 6.1 and 7.0 still pending.

Check
Identify on-premises VeloCloud Orchestrator instances using certificate-based Edge authentication, then apply the fixed 5.2 or 6.4 release and restrict web interface access.
Affected
On-premises orchestrators configured for certificate-based Edge authentication let unauthenticated remote attackers reach internal functions, compromise the host, and pivot to managed Edge devices.
Fix
Upgrade to fixed 5.2 or 6.4 releases, limit orchestrator web access to trusted networks, and monitor for the July flaw already reported exploited.