Ethical Hacking News
A critical vulnerability has been disclosed in Arista's VeloCloud Orchestrator (VCO), a server that manages the Edge devices in a VeloCloud SD-WAN. The CVE-2026-93952 flaw allows a remote attacker with no login access to privilege internal functions and affect the VCO host, with only orchestrators set up to authenticate their Edges with certificates exposed. Arista has already patched the Hosted and Dedicated versions of VCO and provides guidance on mitigating the risk of exposure until a fixed release is installed.
A critical vulnerability (CVE-2026-93952) was found in Arista's VeloCloud Orchestrator (VCO), allowing remote attackers to access internal functions and affect the VCO host. Arista gave the flaw a CVSS score of 10.0, indicating a high level of severity, and reported that it is actively being exploited. The vulnerability is related to the way VeloCloud Edges authenticate with the orchestrator in three modes. Fixed releases are available for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains. Arista recommends taking steps to mitigate the risk of exposure until a fixed release is installed. Signs of compromise include unusual file paths, encoded characters, and high request rates. Incident response is advised after upgrading, which may include rotating credentials, reviewing administrator activity, and restoring or replacing the orchestrator.
Recently, a critical vulnerability was uncovered in Arista's VeloCloud Orchestrator (VCO), a server that manages the Edge devices in a VeloCloud SD-WAN. This flaw, tracked as CVE-2026-93952, allows a remote attacker with no login access to privilege internal functions and affect the VCO host, with only orchestrators set up to authenticate their Edges with certificates exposed. This vulnerability has been actively exploited by attackers.
Arista gave the flaw a CVSS score of 10.0, indicating a high level of severity. A successful attack may compromise the orchestrator and the data it manages. Moreover, a compromised VCO may also give attackers access to the Edge devices it manages. Arista discovered the flaw externally and reported that it is actively being exploited.
The vulnerability is related to the way VeloCloud Edges authenticate with the orchestrator in three modes: Certificate Deactivated mode, Certificate Acquire mode, and Certificate Required mode. In Certificate Deactivated mode, an Edge uses a pre-shared key (PSK). In Certificate Acquire and Certificate Required modes, it uses a certificate issued by the orchestrator. An orchestrator is exposed if "certificate-based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured." The attacker also needs network access to the VCO web interface and the public part of an Edge's authentication certificate.
As of September 22, fixed releases are available for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains. Arista has already patched the Hosted and Dedicated versions of VCO. The affected releases include those that fixed a different VCO flaw, which Arista reported as exploited in July.
Arista recommends taking the following steps to mitigate the risk of exposure until a fixed release is installed: Limit access to the VCO web interface to trusted administrative networks. Monitor the VCO for access from known malicious IP addresses. Monitor for unexpected outbound network traffic from the VCO host. Consider blocking outbound ports that are not required for normal operation. Monitor for backdoor daemons and webshells. Review recent administrator activity for unexpected changes.
Arista also provided signs of compromise for the VCO, including files with unusual URL-like paths, encoded characters, references to local or internal services, or high request rates. The specific indicators to look for are:
File
:
/usr/local/sbin/.vcnode.js
File
:
/usr/local/sbin/vc-sysmond
MD5
(
vc-sysmond
):
dc78e206eaeadec59fc5801fe4556bd0
File
:
/etc/systemd/system/vc-sysmon.service
HTTP header
in nginx logs:
x-vc-opt
IP
:
142.93.149[.]77
IP
:
104.248.126[.]159
If any of these indicators are found, preserve the state of the VCO and contact TAC or your Arista account team. If a suspected compromise is detected, save the VCO's web access, backend application, system, and database logs and its file-system timestamps before fixing anything.
Arista advises incident response after upgrading. That may include rotating credentials, reviewing administrator activity, checking the state of managed Edge devices, and restoring or replacing the orchestrator from trusted sources.
Related Information:
https://www.ethicalhackingnews.com/articles/Arista-Discloses-Critical-VeloCloud-Orchestrator-Flaw-Exploited-by-Attackers-in-Certificate-Based-Setups-ehn.shtml
https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html
Published: Tue Sep 22 09:13:51 2026 by llama3.2 3B Q4_K_M