Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Vulnerability in VeloCloud Orchestrator Exploited

Critical Vulnerability in VeloCloud Orchestrator Exploited

Posted on September 22, 2026 By CWS

On September 22, Arista Networks disclosed a critical security vulnerability identified in the on-premises VeloCloud Orchestrator (VCO), a key component in managing VeloCloud SD-WAN devices. This vulnerability, cataloged as CVE-2026-93952, is reportedly being actively exploited by attackers. The flaw permits unauthorized access to internal functionalities, affecting orchestrators configured to authenticate Edges using certificates.

Implications of the Vulnerability

The flaw, rated with a CVSS 3.1 score of 10.0, underscores its severity and potential impact. When exploited, attackers can compromise the orchestrator, jeopardizing the data it manages and potentially gaining control over the network Edge devices. Arista has issued patches for some release versions, but updates for the 6.1 and 7.0 release trains remain pending.

Arista’s advisory highlights that orchestrators using certificate-based authentication for VeloCloud Edges are susceptible to this flaw. However, the exact modes of certificate-based authentication that expose the orchestrator were not detailed. The vulnerability requires network access to the VCO web interface and the public part of an Edge’s authentication certificate.

Current and Future Mitigation Measures

Arista has released fixes for specific versions within the 5.2 and 6.4 trains, but the 6.1 and 7.0 versions still await updates. The company assures that patches for supported trains will be announced in their security advisories. Customers operating unsupported versions are encouraged to consult Arista’s Technical Assistance Center (TAC) for upgrade options.

In the interim, Arista recommends several precautionary measures: restricting access to the VCO web interface to trusted networks, monitoring for known malicious IP addresses, and observing for unusual outbound network activity. It is also advised to block unnecessary outbound ports and monitor for signs of unauthorized access or modifications.

Identifying and Responding to Compromise

Detecting a breach through this vulnerability requires vigilance, as no singular indicator confirms exploitation. Review VCO web access logs for unusual activity, such as requests with atypical paths or high frequencies. Indicators include specific file modifications or the presence of certain IP addresses known to be associated with malicious activity.

Should any signs of compromise be observed, administrators are advised to preserve the system’s current state and contact Arista’s TAC for further instructions. After securing the system, an incident response protocol should be initiated, including credential rotation and a thorough review of the orchestrator’s and Edge devices’ integrity.

This vulnerability highlights the ever-evolving landscape of cybersecurity threats and the importance of timely updates and vigilant monitoring to protect network infrastructures.

The Hacker News Tags:Arista, certificate-based authentication, CVE-2026-93952, cyber attack, cyber threats, Cybersecurity, incident response, IT security, network security, network vulnerability, SD-WAN, security patch, system upgrade, VeloCloud, Vulnerability

Post navigation

Previous Post: Aikido Security Launches Altar-1 AI for Cybersecurity
Next Post: Chinese Hackers Exploit ZyXEL Switch Vulnerability

Related Posts

TikTok Forms U.S. Joint Venture to Continue Operations Under 2025 Executive Order TikTok Forms U.S. Joint Venture to Continue Operations Under 2025 Executive Order The Hacker News
RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More Stories RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More Stories The Hacker News
Critical GitLab Flaw Allows Project Deletion Risk Critical GitLab Flaw Allows Project Deletion Risk The Hacker News
Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security The Hacker News
CISA Highlights Exploited Roundcube Vulnerabilities CISA Highlights Exploited Roundcube Vulnerabilities The Hacker News
Critical Cisco SD-WAN Vulnerability Exploited Since 2023 Critical Cisco SD-WAN Vulnerability Exploited Since 2023 The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical SharePoint Flaw Enables Remote Code Execution
  • Cyera Secures $400M, Reaches $12B Valuation
  • Critical Linux Kernel Bug Threatens ARM64 Systems
  • Critical ARM64 Linux Vulnerability Exposes Hosts
  • Chinese Hackers Exploit ZyXEL Switch Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical SharePoint Flaw Enables Remote Code Execution
  • Cyera Secures $400M, Reaches $12B Valuation
  • Critical Linux Kernel Bug Threatens ARM64 Systems
  • Critical ARM64 Linux Vulnerability Exposes Hosts
  • Chinese Hackers Exploit ZyXEL Switch Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark