EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

Editorial source
Editorial OSINT source. The content is an indication to verify with independent institutional or technical sources before operational decisions.
EudorIA operational summary

What it means

Priority 95/100

Un'azienda ha rilevato un difetto critico in VeloCloud Orchestrator (VCO), con CVE-2026-93952, sfruttato attivamente in ambienti con autenticazione certificata. L'attacco permette a un attaccante remoto di compromettere il VCO e i dispositivi Edge. Le versioni 5.2 e 6.4 sono state corrette, mentre 6.1 e 7.0 non lo sono ancora. Arista ha rilasciato patch per le versioni Hosted e Dedicated.

Why it matters

Per le PMI italiane, un attacco al VCO potrebbe compromettere la gestione della rete SD-WAN e i dispositivi Edge, mettendo a rischio la sicurezza e la continuità operativa. La mancanza di patch per alcune versioni aumenta il rischio di esposizione.

Potential operational benefits

  • Riduzione della superficie esposta del VCO
  • Miglioramento della rilevazione di accessi non autorizzati
  • Riduzione del rischio di compromissione dei dispositivi Edge
  • Miglioramento della gestione incidenti e ripristino
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementFirewall NGFW / IPSMonitoraggio / SIEMSegmentazione di reteBackup & DR
AudienceITSOCCISO
Information centre

Translation in progress

The Hacker News

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are

Source
The Hacker News
Publishing entity
The Hacker News
Entity type
editorial osint
Area
Global
Original language
en · translation in preparation
Publication
22/09/2026 14:29
MITRE ATT&CK
T1190, T1486
CVE
CVE-2026-93952
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source