What it is
CVE-2026-93952 is an unauthenticated Security Advisory 0183 affecting Arista Networks VeloCloud Orchestrator (VCO) On-Prem. VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote...
Vulnerability report
Security Advisory 0183
Arista Networks / VeloCloud Orchestrator (VCO) On-Prem · 5.2.0 to <= 5.2.3.15
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-93952 is an unauthenticated Security Advisory 0183 affecting Arista Networks VeloCloud Orchestrator (VCO) On-Prem. VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote...
Is it exploited?
Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
Arista Networks / VeloCloud Orchestrator (VCO) On-Prem 5.2.0 to <= 5.2.3.15.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
Hosted, including Dedicated, versions of VCO were impacted and have already been patched.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Arista
A trusted third party reported exploitation.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Arista First | 2026-09-22 10:06 UTC |
| The Hacker News | 2026-09-22 13:31 UTC |
| TheHackerNews | 2026-09-22 14:22 UTC |
| CISA | 2026-09-22 19:50 UTC |
| CVE | 2026-09-22 20:01 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS
0.7%
Recent mention · The Hacker News
Swati KhandelwalSep 22, 2026Vulnerability / Network Security Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may...
Read full advisoryCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Recent mention · The Hacker News
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based SetupsThe Hacker News · 22 Sep 2026
Swati KhandelwalSep 22, 2026Vulnerability / Network Security Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are exposed. As of September 22, fixed releases are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains. Arista has...
Recent mention · Arista
Security Advisory 0183Arista · 21 Sep 2026
Date: September 22, 2026 Revision Date Changes 1.0 September 22, 2026 Initial release The CVE-ID tracking this issue: CVE-2026-93952 CVSSv3.1 Base Score: 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSSv4.0 Base Score: 9.5 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) Common Weakness Enumeration: CWE-20: Improper Input Validation This vulnerability is being tracked by BUG1907167, and BUG1937417. Description VeloCloud Orchestrator (VCO) on-pre ...
Timeline
20:01 UTC
Exploitation attested by an external source
19:50 UTC
Listed in the CISA Known Exploited Vulnerabilities catalog
14:22 UTC
Exploitation attested by an external source
13:31 UTC
Exploitation attested by an external source
10:06 UTC
High-confidence, third-party attested exploitation
07:37 UTC
Vulnerability disclosed publicly
01:37 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-93952
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-93952",
"confidence": "Confirmed",
"cvss_score": 9.5,
"cvss_estimated": false,
"epss_score": 0.00741,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}