Interestana
Home/News/CVSS 10.0 VeloCloud Orchestrator Flaw Exploited
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

CVSS 10.0 VeloCloud Orchestrator Flaw Exploited

CVSS 10.0 VeloCloud Orchestrator Flaw Exploited

Arista disclosed on September 22 that attackers are actively exploiting a critical vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments. This flaw, designated CVE-2026-93952, carries a CVSS 10.0 severity score, indicating the highest possible risk. The vulnerability affects the server responsible for managing Edge devices within a VeloCloud Software-Defined Wide Area Network (SD-WAN) infrastructure. Exploitation of CVE-2026-93952 does not require any prior authentication or login credentials, allowing a remote attacker to potentially gain unauthorized access and execute internal functions. This could lead to a compromise of the VCO host system itself, granting attackers significant control over the network management environment.

The vulnerability specifically impacts VeloCloud Orchestrator instances that are configured to authenticate their Edge devices using digital certificates. This certificate-based authentication method is a common security practice for establishing trust between network components. However, in this instance, the implementation of certificate authentication has a critical weakness that attackers are leveraging. The precise technical details of how the certificate-based authentication is bypassed or manipulated to achieve privilege escalation are not fully detailed in the initial advisory, but the implication is that the integrity of the authentication process is compromised.

VeloCloud SD-WAN, a product line now owned by Arista Networks, provides a cloud-managed solution for deploying and managing wide area networks. It allows organizations to create flexible, scalable, and secure network connections between their branches, data centers, and cloud environments. The Orchestrator is the central management component that provides visibility, control, and policy enforcement across the entire SD-WAN fabric. A compromise of the Orchestrator could therefore have far-reaching consequences, potentially disrupting network operations, enabling lateral movement within an organization's network, and facilitating data exfiltration.

Arista has indicated that they are working on a permanent fix for this vulnerability and have provided guidance to affected customers. Organizations utilizing VeloCloud Orchestrator with certificate-based authentication are strongly advised to review Arista's security advisories and implement any recommended mitigation steps immediately. While the exact timeline for a patch release is not specified, the active exploitation of this flaw underscores the urgency of addressing the security risk. The disclosure of a CVSS 10.0 vulnerability that is already being exploited highlights the persistent threat landscape for network infrastructure and the importance of timely security updates and robust security monitoring.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next