Arista VeloCloud Orchestrator flaw exploited in wild
A path traversal bug in on-prem Arista VeloCloud Orchestrator (CVE-2026-93952, CVSS 9.5) is being actively exploited to gain privileged internal access.
NCSC-NL has published an advisory for a path traversal vulnerability (CVE-2026-93952, CVSS v4 9.5) in Arista's VeloCloud Orchestrator (VCO) on-premises deployments. The flaw allows remote, unauthenticated attackers to reach privileged internal functionality, impacting confidentiality, integrity and availability of the orchestrator, which centrally manages SD-WAN edge devices. Arista's hosted VCO environments have already been remediated, and updates are now available for on-premises installations.
The advisory explicitly states the vulnerability is being actively exploited, making patching a priority for any organisation running self-hosted VCO. NCSC-NL recommends restricting access to the VCO web interface to trusted administrative networks to reduce exposure, and monitoring environments for signs of compromise. Defenders should consult Arista's linked security advisory for indicators of compromise and patch details, as VCO compromise could enable broader control over an organisation's SD-WAN infrastructure.
Mentioned in this report
Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0385.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free