Latest

A new CVSS 10.0 vulnerability in Arista’s VeloCloud Orchestrator is being actively exploited against certificate-authenticated deployments, the second perfect-severity-score flaw to hit the platform in 2026, and patches still aren’t available for two of its four release trains.

Arista Networks is now managing its second maximum-severity, actively-exploited vulnerability this year in VeloCloud Orchestrator (VCO), the SD-WAN management platform it acquired from Broadcom in a deal that closed in mid-2025. The new flaw, tracked as CVE-2026-93952, carries a perfect CVSS 10.0 score and is already being exploited against internet-facing deployments, with patches still unavailable for half of the product’s active release trains.

The Flaw: CVE-2026-93952

The vulnerability affects on-premises VCO deployments configured for Edge certificate-based authentication. An unauthenticated remote attacker who can reach the orchestrator’s web interface and obtain the public portion of an Edge device’s authentication certificate (not a secret, and often recoverable from network traffic or a compromised branch appliance) can “privilege internal functions and affect the VCO host,” according to Arista’s advisory. No login credentials are required at any stage of the attack.

Two Release Trains Still Have No Fix

Arista has patched two of the product’s four active release trains as of September 22: the 5.2 line (versions 5.2.3.15 and earlier) is fixed in 5.2.3.16, and the 6.4 line is fixed in 6.4.2.8. The 6.1 line (6.1.3.7 and earlier) and the 7.0 line (7.0.0.2 and earlier) remain unpatched, leaving customers on those trains with no remediation beyond disabling certificate-based Edge authentication entirely. Arista confirmed the flaw “was discovered externally and is known to be actively exploited” but declined to say how long attackers had been exploiting it before discovery or how many organizations have been affected. Researchers have published indicators of compromise, including a payload file hash and two source IP addresses tied to observed attacks.

A Second CVSS 10.0 in Three Months

This is not VeloCloud Orchestrator’s first perfect-severity disclosure this year. In July, Arista patched CVE-2026-16812, a separate CVSS 10.0 command-injection flaw that required no authentication or special configuration at all and affected every release train by default, a bug serious enough that CISA added it to its Known Exploited Vulnerabilities catalog within days, giving federal agencies just three days to patch under Binding Operational Directive 26-04. Two maximum-severity, actively-exploited zero-days in the same orchestrator inside one fiscal quarter is a pattern, not a coincidence, and it raises pointed questions about how much latent risk remains in the codebase Arista inherited when it took over the VeloCloud line from Broadcom. VeloCloud’s SD-WAN technology predates that acquisition by close to a decade, having passed through VMware’s ownership before Broadcom’s 2023 buyout of VMware brought it along, meaning Arista is now the third corporate parent responsible for a code lineage that has changed hands twice in three years, with security ownership resetting each time.

Why Orchestrator-Level Flaws Are the Nightmare Scenario for SD-WAN

VCO isn’t a single device; it’s the centralized controller that configures every Edge appliance across an enterprise’s entire wide-area network. An attacker with orchestrator-level access can push malicious configuration to every branch office at once, intercept or reroute inter-site traffic, and pivot into whatever internal network segments those edges terminate into. That blast radius is categorically worse than a single compromised device, and it directly undercuts the value proposition retail, healthcare, and logistics customers bought VeloCloud for in the first place: centralizing WAN control into one console. When that console becomes the attack surface, centralization stops being an advantage.

What Security Teams Should Do Right Now

Because there’s no complete patch across the product line, incident responders are recommending detection over remediation for customers still on the 6.1 and 7.0 trains. That means checking web access logs for unusual URL paths hitting the orchestrator, reviewing backend and system logs for follow-up activity after any suspicious request, and hunting specifically for unexpected command execution, unplanned database exports, and credential-access attempts originating from the VCO host itself. Organizations that can disable certificate-based Edge authentication until a fix ships for their train should do so; those that can’t should treat every VCO instance exposed to the internet as presumed-compromised until proven otherwise, given Arista’s own acknowledgment that the flaw was found through external disclosure rather than internal testing.

The Competitive Read: SD-WAN Security Becomes a Differentiator

Two perfect-severity, actively-exploited flaws in the same product line within one year land at exactly the moment enterprise SD-WAN buyers are consolidating vendor shortlists ahead of contract renewals. Cisco’s Catalyst SD-WAN (formerly Viptela), Palo Alto Networks’ Prisma SD-WAN, and Fortinet’s Secure SD-WAN are all selling centralized-orchestrator architectures on the opposite pitch Arista now has to make defensively: that a compromised login isn’t required to take over the control plane. For enterprise security teams running vendor risk scorecards during renewal season, a repeat CVSS-10.0 disclosure inside a single 90-day window is the kind of signal that shows up as a deduction on paper, not just a CVE to patch. Arista’s task now is proving that VeloCloud’s Broadcom-era architecture doesn’t have more of these waiting before a competitor makes that argument for them.

Leave a Reply

Discover more from Biz Tech Journals

Subscribe now to keep reading and get access to the full archive.

Continue reading