Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
This article is based primarily on reporting from The Hacker News, corroborated by secondary sources; no direct vendor advisory is available. Arista Networks confirmed on September 22, 2026, that CVE-2026-93952, a maximum-severity vulnerability in the on-premises VeloCloud Orchestrator, is being actively exploited in the wild. The bug affects deployments that have enabled certificate-based authentication between Edge and Orchestrator. Fixed releases are available only for the 5.2 and 6.4 trains, leaving the 6.1 and 7.0 branches unprotected.
- CVE-2026-93952 carries a CVSS 3.1 score of 10.0: network access, no privileges required, complete impact on confidentiality, integrity, and availability with changed scope.
- Active exploitation is confirmed by Arista with the phrasing "discovered externally and is known to be actively exploited"; according to The Hacker News reporting, the attacker "requires no existing operator credentials."
- The vector depends on the certificate-based configuration: deployments in PSK mode are not exposed.
- The patching matrix is incomplete: 5.2.3.16+ and 6.4.2.8+ are available, but for 6.1.3.7 and earlier and 7.0.0.2 and earlier Arista has not yet released fixes.
Verified Facts
The Mechanism
The vulnerability resides in a flaw in the web interface of the on-premises VeloCloud Orchestrator. According to The Hacker News reporting, an attacker with network access to the VCO web interface and in possession of the public portion of the Edge authentication certificate can access internal functionality without providing operator credentials.
SecurityOnline.info adds that the environment must explicitly configure certificate-based authentication: this is a stringent condition that segments the target population. Installations using pre-shared key (PSK) remain outside the documented attack surface.
TheHackerWire published the full CVSS vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. The S:C (Scope Changed) parameter signals that compromise of the orchestrator can extend compromise beyond the initial component, toward managed Edge devices.
Exploitation Evidence and Indicators of Compromise
Arista provided a specific technical indicator: the vc-sysmond file with MD5 hash dc78e206eaeadec59fc5801fe4556bd0, located at /etc/systemd/system/vc-sysmon.service. The Hacker News reports that this element emerged in the context of investigations into compromised systems, although it is unclear whether it represents an original payload or a post-exploitation artifact.
Strix.ai, citing the CNA record on CVE.org, confirms the vulnerability structure but notes that NVD analysis is still in progress. Convergence on the fundamental data — CVE, score, affected products, attack mode — is solid across four primary sources.
"This issue was discovered externally and is known to be actively exploited." — Arista Networks, via The Hacker News reporting
The Patching Matrix
The patch distribution reflects a fragmented release management. Arista has made fixes available for the 5.2 train from version 5.2.3.16 onward and for the 6.4 train from version 6.4.2.8 onward. Affected versions are: 5.2.3.15 and earlier; 6.1.3.7 and earlier; 6.4.2.7 and earlier; 7.0.0.2 and earlier.
The critical point is the lack of releases for the 6.1 and 7.0 trains. Organizations on these branches have no secure upgrade path. Arista has not communicated a timeline for completing coverage. Hosted and Dedicated VeloCloud Orchestrator instances, managed directly by the vendor, are already updated according to all primary sources.
Analysis and Context
The Recurring Pattern on VCO
CVE-2026-93952 is not an isolated event. In July 2026, CVE-2026-16812 emerged, also rated CVSS 10.0, affecting the same on-premises platform product. The temporal correlation — two maximum-severity vulnerabilities on the same platform in roughly two months — suggests that SD-WAN orchestrators have become a recurring initial-access vector for offensive actors.
The difference between the two flaws is distinct. CVE-2026-16812 involved a command injection in configuration profile management, with different impact and distinct attack conditions. The releases that fixed it — 5.2.3.14, 6.1.3.4, 6.4.2.4 — are used by The Hacker News as a version-matrix reference point, but do not technically overlap with CVE-2026-93952. They are distinct CVEs with different mechanisms and prerequisites.
The Secure Configuration Paradox
An element of tension emerges from the verified facts: certificate-based authentication, standardly considered more robust than PSK, is precisely the prerequisite that exposes the vulnerability. Organizations that adopted this configuration to elevate their security posture now find themselves in the at-risk population, while PSK deployments — typically judged less secure — remain outside the documented attack surface. This inversion does not invalidate general best practices, but underscores that risk assessment must always integrate platform-specific known-vulnerability intelligence.
Immediate Actions
Verify the Edge-Orchestrator authentication mode. Organizations must immediately determine whether their on-premises installation uses certificate-based authentication: only these configurations are exposed.
Apply available patches. For the 5.2 and 6.4 trains, upgrade respectively to 5.2.3.16 or later and 6.4.2.8 or later.
Assess posture for trains without fixes. For versions 6.1 and 7.0, Arista has not released corrections as of September 22, 2026. Options include migrating to supported trains or awaiting vendor updates.
Monitor indicators of compromise. Check for the presence of the vc-sysmond file with MD5 hash dc78e206eaeadec59fc5801fe4556bd0 at /etc/systemd/system/vc-sysmon.service.
Source Limitations and Uncertainties
It is not known when attacks began, nor the volume or scope of exploitation. No public proof-of-concept has been identified, nor has a specific actor been attributed. Arista has not specified which certificate-based authentication mode (Certificate Acquire or Certificate Required) is vulnerable. The timeline for patches for the 6.1 and 7.0 trains has not been communicated.
Information is based on sources available at the time of publication.
Information has been verified against cited sources and updated as of the time of publication.
Sources
- https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html
- https://blog.netmanageit.com/new-cvss-10-0-velocloud-orchestrator-flaw-actively-exploited-in-certificate-based-setups/
- https://securityonline.info/velocloud-vulnerability-cve-2026-93952/
- https://www.thehackerwire.com/vulnerability/CVE-2026-93952/
- https://www.strix.ai/cve/CVE-2026-93952
- https://cybersecuritynews.com/velocloud-command-injection-exploit/
- https://thehackernews.com/
- https://thehackernews.com/p/upcoming-hacker-news-webinars.html
- https://thehackernews.com/search/label/Threat%20Intelligence
- https://thehackernews.com/search/label/Vulnerability
- https://thehackernews.com/search/label/Cyber%20Attack
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.