VORANT. Threat Intelligence Sign in Get the full feed

Arista VeloCloud Orchestrator flaw exploited in wild

high vulnerability telecommunicationsinfrastructure

A path traversal bug in on-prem Arista VeloCloud Orchestrator (CVE-2026-93952, CVSS 9.5) is being actively exploited to gain privileged internal access.

NCSC-NL has published an advisory for a path traversal vulnerability (CVE-2026-93952, CVSS v4 9.5) in Arista's VeloCloud Orchestrator (VCO) on-premises deployments. The flaw allows remote, unauthenticated attackers to reach privileged internal functionality, impacting confidentiality, integrity and availability of the orchestrator, which centrally manages SD-WAN edge devices. Arista's hosted VCO environments have already been remediated, and updates are now available for on-premises installations.

The advisory explicitly states the vulnerability is being actively exploited, making patching a priority for any organisation running self-hosted VCO. NCSC-NL recommends restricting access to the VCO web interface to trusted administrative networks to reduce exposure, and monitoring environments for signs of compromise. Defenders should consult Arista's linked security advisory for indicators of compromise and patch details, as VCO compromise could enable broader control over an organisation's SD-WAN infrastructure.

Mentioned in this report

Vulnerabilities CVE-2026-93952KEV

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0385.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free