Arista Urges Immediate Patching of Exploited VCO Zero-Day

https://www.securityweek.com/wp-content/uploads/2026/09/arista.jpeg

Networking solutions provider Arista has released urgent patches for a critical-severity vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments that has been exploited as a zero-day.

VCO is a centralized management tool for configuring, monitoring, and orchestrating edge devices, policies, and traffic in Arista VeloCloud SD-WAN.

The exploited zero-day, tracked as CVE-2026-93952 (CVSS score of 10), is described as an improper input validation issue that could allow remote attackers to access privileged internal functionality.

Successful exploitation of the security defect could impact the confidentiality, integrity, and availability of the orchestrator and the data it manages.

“This issue was discovered externally and is known to be actively exploited,” Arista warns.

According to the company, the bug affects only VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom) and was resolved in VCO versions 5.2.3.16 and 6.4.2.8 in the 5.2.x and 6.1.x trains, respectively. Patches for other trains will also be released.

Advertisement....

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE