Active Exploitation Alert: Arista VeloCloud Orchestrator Unauthenticated Privileged Access (CVE-2026-93952) Added to CISA KEV — CVSS 10.0 Control-Plane Risk to Managed Edges

Active Exploitation Alert: Arista VeloCloud Orchestrator Unauthenticated Privileged Access (CVE-2026-93952) Added to CISA KEV — CVSS 10.0 Control-Plane Risk to Managed Edges

Executive Summary

CVE-2026-93952 is a critical improper input validation vulnerability (CWE-20) in Arista Networks VeloCloud Orchestrator (VCO) On-Prem (formerly VeloCloud Orchestrator by Broadcom). Arista rates the issue CVSS 3.1 10.0 Critical (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) and CVSS 4.0 9.5 Critical. A remote attacker may access privileged internal functionality and impact the VCO host, compromise confidentiality, integrity, and availability of the orchestrator and data it manages, and—per Arista—a compromised VCO may allow access to managed VeloCloud Edge devices.

Exploitation does not require VCO tenant/operator credentials. Exposure applies only when certificate-based Edge→VCO authentication is configured, and the attacker needs network access to the VCO web UI plus the public portion of a VeloCloud Edge authentication certificate.

Arista Security Advisory 0183 (Rev 1.0, September 22, 2026) states the issue was discovered externally and is known to be actively exploited. CISA added CVE-2026-93952 to the Known Exploited Vulnerabilities catalog on September 22, 2026, with a federal remediation due date of September 25, 2026, forensic triage required = Yes, and known ransomware campaign use = Unknown. NVD status is Awaiting Analysis as of September 23, 2026 (lastModified September 23, 2026).

Fixed as of the advisory: 5.2.3.16+ (5.2.3 train) and 6.4.2.8+ (6.4.2 train). Fixes for other supported trains are pending. Hosted/Dedicated VCO is impacted but Arista states it is already patched. No public threat-actor attribution appears in Arista, CISA, or NVD materials reviewed for this advisory.

Technical Information

Per Arista SA-0183, CVE-2026-93952 is improper input validation enabling unauthenticated privileged access to internal VCO functionality when certificate-based Edge authentication is in use. The attacker needs:

  1. Certificate-based authentication from VeloCloud Edge to VCO configured.
  2. Access to the public portion of the Edge authentication certificate.
  3. Network access to the VCO web interface.
  4. No VCO tenant/operator credentials.

Arista Edge auth modes include Certificate Deactivated (PSK), Certificate Acquire, and Certificate Required. Arista has not specified which of Acquire/Required satisfy the "certificate based authentication" exposure prerequisite; do not invent that mapping.

Vendor BUG trackers: BUG1907167, BUG1937417. Related prior context (not this CVE): July actively exploited VCO flaw CVE-2026-16812 (different exposure model—default exposure, not cert-config dependent) is contextual only.

Primary sources reviewed (Arista SA-0183, CISA KEV, NVD, The Hacker News) do not explicitly map CVE-2026-93952 to MITRE ATT&CK technique IDs. This advisory does not invent ATT&CK mappings or APT attribution.

Affected Product Versions

Vendor: Arista Networks. Affected product: VeloCloud Orchestrator On-Prem.

Affected software trains (Arista SA-0183):

  • 5.2.3.15 and below in the 5.2.x train
  • 6.1.3.7 and below in the 6.1.x train
  • 6.4.2.7 and below in the 6.4.x train
  • 7.0.0.2 and below in the 7.0.x train

NVD/CVE product ranges (vendor CPE-style): affected from 5.2.0 through 5.2.3.15; 6.1.0 through 6.1.3.7; 6.4.0 through 6.4.2.7; 7.0.0 through 7.0.0.2. Default status outside listed ranges: unaffected.

Fixed as of 2026-09-22 advisory:

  • VCO 5.2.3.16 and later in the 5.2.3 train
  • VCO 6.4.2.8 and later in the 6.4.2 train
  • Other release trains: fixes pending; advisory to be updated; unsupported trains → contact Arista TAC

Hosted / Dedicated VCO: impacted; already patched (vendor).

Explicitly not affected (Arista list includes): VeloCloud Gateway; VeloCloud Edge; Arista EOS-based switching/routing platforms; CloudVision family; Wi-Fi APs; DMF; NDR; NG Firewall/Micro Edge; NetVisor; and other platforms listed on SA-0183.

Workaround and Mitigation

Until fixed software is applied (Arista):

  1. Restrict VCO web interface access to trusted administrative networks.
  2. Monitor VCO for accesses from known malicious source IPs.
  3. Monitor unexpected outbound network activity from the VCO host; consider blocking outbound ports not needed for normal activities.
  4. Monitor for backdoor daemons and webshells.
  5. Review recent administrator activity for unexpected changes.

Resolution: Upgrade to a remediated VCO release as soon as possible. Prefer 5.2.3.16+ or 6.4.2.8+ where available; escalate Arista TAC for 6.1.x / 7.0.x or unsupported trains.

Because CISA KEV requires forensic triage (Yes) under BOD 26-04 with due date September 25, 2026 for FCEB, do not close residual risk on "version bumped" alone—hunt IoCs and preserve evidence before remediating where feasible.

Post-remediation (Arista): credential rotation; review admin activity; validate managed Edge device state; restore/replace orchestrator from trusted sources. Compromises to VCO may allow attackers access to Edge devices.

Indicators of Compromise

Arista discloses IoCs for this issue (no single definitive IoC). Do not invent extras.

Files / artifacts (Arista):

  • /usr/local/sbin/.vcnode.js
  • /usr/local/sbin/vc-sysmond — known malicious MD5: dc78e206eaeadec59fc5801fe4556bd0
  • /etc/systemd/system/vc-sysmon.service

HTTP (Arista):

  • Header in nginx logs: x-vc-opt

IPs (Arista):

  • 142.93.149.77
  • 104.248.126.159

Behavioral review guidance (Arista): unusual URL-like path components, encoded characters, references to local/internal services, high request rates; unexpected outbound HTTP/HTTPS from VCO; sensitive config changes without admin activity; privileged maintenance actions outside expected workflows; unexpected command execution / file creation / DB export / archives; unexpected access to DB contents, config, inventory, credentials, certificates, or key material.

If IoCs are found: preserve VCO state; contact Arista TAC/account team. If compromise is suspected: preserve web access, backend app, system, and DB logs and filesystem timestamps before remediation where feasible.

Primary sources do not publish MITRE ATT&CK technique IDs for this CVE. Do not invent ATT&CK mappings.

References

Third-Party Risk Bridge: Shared VCO as SD-WAN Control Plane

VeloCloud Orchestrator is the management control plane for enterprise and MSP-managed SD-WAN fleets. Arista states successful exploitation may compromise the orchestrator and the data it manages, and that VCO compromise may allow attackers access to managed Edge devices. In certificate-based setups, the exposure is unauthenticated once an attacker has VCO web reachability and the public portion of an Edge auth certificate. Ask every MSP or vendor-managed SD-WAN provider whether they operate on-prem VCO versus Hosted/Dedicated (vendor says Hosted/Dedicated already patched), whether certificate-based Edge→VCO authentication is enabled, whether the VCO web UI is internet-exposed, which train they run against Arista's ceilings (5.2.3.15 / 6.1.3.7 / 6.4.2.7 / 7.0.0.2), and whether IoC hunt plus Edge-state validation were completed before declaring residual risk closed—urgency is CVSS 10.0, active exploitation, KEV due September 25, 2026, and incomplete fixed-train coverage for 6.1/7.0.

Book a demo to see how Rescana tracks SD-WAN and MSSP vendors for KEV-class orchestrator control-plane risk, version attestation, and forensic-triage evidence.

Forward this advisory to your TPRM owner if an MSP or managed SD-WAN provider operates a VCO that manages your Edges—they own the version, cert-mode, exposure, IoC-hunt, and Edge-state validation asks above.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.