• CISA KEV
  • EXPLOITED

CVE-2026-93952: pre-auth privileged access in Arista VeloCloud Orchestrator

Remote attackers can access privileged internal functionality on Arista VeloCloud Orchestrator (VCO), potentially compromising confidentiality, integrity, and availability. CVE-2026-93952 is an improper input validation flaw (CWE-20) affecting on-prem VCO releases listed below; exploitation requires network access to the vulnerable VCO instance and does not require user interaction or authentication per the CVSS vector. Affected versions include 5.2.0–5.2.3.15, 6.1.0–6.1.3.7, 6.4.0–6.4.2.7, and 7.0.0–7.0.0.2.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.01062
CWE
CWE-20
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: CISA added this CVE to its Known Exploited Vulnerabilities catalog with a federal fix deadline, so prioritize mitigation for internet-exposed VeloCloud Orchestrator instances immediately.

What is CVE-2026-93952?

Remote attackers can access privileged internal functionality on Arista VeloCloud Orchestrator (VCO), potentially compromising confidentiality, integrity, and availability. CVE-2026-93952 is an improper input validation flaw (CWE-20) affecting on-prem VCO releases listed below; exploitation requires network access to the vulnerable VCO instance and does not require user interaction or authentication per the CVSS vector. Affected versions include 5.2.0–5.2.3.15, 6.1.0–6.1.3.7, 6.4.0–6.4.2.7, and 7.0.0–7.0.0.2.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Arista VeloCloud Orchestrator are affected?

BRANCHAFFECTEDFIXED
5.x5.2.0 – 5.2.3.15
6.x6.1.0 – 6.1.3.7
6.x6.4.0 – 6.4.2.7
7.x7.0.0 – 7.0.0.2

Is CVE-2026-93952 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-22, and US federal agencies must address it by 2026-09-25.

How to fix CVE-2026-93952

  1. Isolate and restrict network access to on-prem VeloCloud Orchestrator instances from untrusted networks and the internet.
  2. Follow Arista's vendor guidance and apply any mitigations the vendor provides as a priority.
  3. Monitor VCO logs and network traffic for anomalous activity and signs of exploitation.
  4. If vendor mitigations are unavailable and the instance is cloud-exposed, consider discontinuing use or relocating services per CISA guidance.

Frequently asked questions

Is CVE-2026-93952 being actively exploited?

CISA added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog on 2026-09-22, requiring federal remediation by 2026-09-25.

Which VeloCloud Orchestrator versions are affected by CVE-2026-93952?

Affected on-prem VeloCloud Orchestrator versions are 5.2.0–5.2.3.15, 6.1.0–6.1.3.7, 6.4.0–6.4.2.7, and 7.0.0–7.0.0.2 according to the vendor data.

Is there a patch for CVE-2026-93952?

No fixed versions are listed for the affected VeloCloud Orchestrator branches; apply vendor mitigations and restrict exposure as advised.

Does CVE-2026-93952 require authentication?

The vulnerability in VeloCloud Orchestrator does not require authentication and can be exploited over the network without user interaction.

References