Threat Intel · SINGAPORE
Arista Confirms Actively Exploited VeloCloud Orchestrator Flaw
By Priya Shah, Threat Intel, Singapore

SINGAPORE - Arista Advisory 0183, published September 22, 2026 and revised to 1.1 on September 23, 2026, covers CVE-2026-93952 in the on-premises VeloCloud Orchestrator. The flaw was discovered externally and is actively exploited.
The advisory classifies the issue as CWE-20. It scores 10.0 on CVSS 3.1 and 9.5 on CVSS 4.0. Arista tracks it as BUG1907167 and BUG1937417.
A remote attacker can gain privileged or host access on an affected on-premises VeloCloud Orchestrator. That access can compromise the confidentiality, integrity, and availability of the orchestrator and of managed data, and it can reach managed Edge devices.
Hosted orchestrators, including Dedicated VCO, were impacted and have been patched. The attack requires certificate-based Edge-VCO authentication, VCO web access, and a public Edge certificate. It does not require tenant or operator credentials.
Affected on-premises releases are 5.2.3.15 and earlier, 6.1.3.7 and earlier, 6.4.2.7 and earlier, and 7.0.0.2 and earlier. End-of-support releases, Gateway, and Edge are not affected. Fixed builds are 5.2.3.16 and later, and 6.4.2.8 and later. Fixes for the other affected trains are forthcoming. Unsupported releases are handled through TAC.
Until a fix is in place, restrict the orchestrator user interface to trusted administrator networks. Monitor for malicious IP addresses, unexpected outbound connections, backdoors, webshells, and unusual administrator activity.
Published indicators are not definitive on their own. They are the file /usr/local/sbin/.vcnode.js, the file /usr/local/sbin/vc-sysmond with MD5 dc78e206eaeadec59fc5801fe4556bd0, the unit /etc/systemd/system/vc-sysmon.service, an nginx header named x-vc-opt, and the addresses 142.93.149.77 and 104.248.126.159. Hunt for odd URL components, unusual encoding, internal references, and high request rates.
CISA added CVE-2026-93952 to the Known Exploited Vulnerabilities catalog on September 22, 2026, with a federal remediation due date of September 25, 2026. The entry calls for forensic triage under Binding Operational Directive 26-04. Known ransomware campaign use is unknown.
For security operations teams, inventory orchestrators that use certificate-based Edge authentication and prioritize those with a reachable user interface. Apply the fixed build, or contact TAC where the train is unsupported. Hunt the published indicators and log anomalies. If exploitation is suspected, preserve logs and timestamps, rotate credentials, validate Edge devices, and restore or replace systems from trusted sources.
Priya Shah covers threat intelligence for SOCtember from Singapore.