Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: velocloud (2 articles)Clear

VeloCloud Orchestrator flaw under active exploitation lets remote attackers compromise SD-WAN management servers

Arista disclosed on September 22 that attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator, the server that manages Edge devices across a VeloCloud SD-WAN. Tracked as CVE-2026-93952 and rated 10.0, it lets a remote attacker with no login reach internal functions and affect the orchestrator host, but only where Edges authenticate using certificates. A compromised orchestrator exposes the data it manages and can give access to the Edge devices under it. Arista says the flaw was found externally and is known to be actively exploited. Fixed releases exist for the 5.2 and 6.4 trains, with 6.1 and 7.0 still pending.

Check
Identify on-premises VeloCloud Orchestrator instances using certificate-based Edge authentication, then apply the fixed 5.2 or 6.4 release and restrict web interface access.
Affected
On-premises orchestrators configured for certificate-based Edge authentication let unauthenticated remote attackers reach internal functions, compromise the host, and pivot to managed Edge devices.
Fix
Upgrade to fixed 5.2 or 6.4 releases, limit orchestrator web access to trusted networks, and monitor for the July flaw already reported exploited.

Critical Arista VeloCloud Orchestrator flaw exploited in attacks

Arista patched a critical vulnerability in on-premises VeloCloud Orchestrator, the console that configures and manages VeloCloud SD-WAN deployments, that is already being exploited. Tracked as CVE-2026-16812 and scored 10.0, it is an unauthenticated operating-system command injection that lets a remote attacker reach privileged functionality meant only for internal use. Arista warns successful exploitation can compromise the confidentiality, integrity, and availability of the orchestrator and everything it manages. There is no configuration that prevents exposure, since the web interface is reachable by default. CISA added it to its exploited-vulnerabilities catalog. Hosted and Dedicated deployments were fixed before the advisory and are not affected.

Check
Identify on-premises VeloCloud Orchestrator instances, upgrade to the fixed 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.x releases immediately, and restrict the web interface to trusted administrative networks.
Affected
Organizations running on-premises VeloCloud Orchestrator (CVE-2026-16812); the web interface is exposed by default, needs no credentials, and active exploitation gives attackers command execution over the orchestrator and managed devices.
Fix
Upgrade to the fixed VCO versions, limit web interface access to trusted networks, and review VCO web access logs for unusual path components, encoded characters, or high request rates.