# Arista VeloCloud Orchestrator flaw exploited in wild

Published: 2026-09-22 · Severity: high · Sectors: telecommunications, infrastructure
Canonical: https://vorant.io/reports/ac4c5d02-235c-5dfb-af34-a9176300c448/arista-velocloud-orchestrator-flaw-exploited-in-wild

> A path traversal bug in on-prem Arista VeloCloud Orchestrator (CVE-2026-93952, CVSS 9.5) is being actively exploited to gain privileged internal access.

NCSC-NL has published an advisory for a path traversal vulnerability (CVE-2026-93952, CVSS v4 9.5) in Arista's VeloCloud Orchestrator (VCO) on-premises deployments. The flaw allows remote, unauthenticated attackers to reach privileged internal functionality, impacting confidentiality, integrity and availability of the orchestrator, which centrally manages SD-WAN edge devices. Arista's hosted VCO environments have already been remediated, and updates are now available for on-premises installations.

The advisory explicitly states the vulnerability is being actively exploited, making patching a priority for any organisation running self-hosted VCO. NCSC-NL recommends restricting access to the VCO web interface to trusted administrative networks to reduce exposure, and monitoring environments for signs of compromise. Defenders should consult Arista's linked security advisory for indicators of compromise and patch details, as VCO compromise could enable broader control over an organisation's SD-WAN infrastructure.

## Mentioned in this report

- Vulnerabilities: CVE-2026-93952 (KEV)

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0385.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ac4c5d02-235c-5dfb-af34-a9176300c448/arista-velocloud-orchestrator-flaw-exploited-in-wild.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
