importantSYS.SOURCE: The Hacker News• 2026-09-22T17:59:00+05:30
Critical CVSS 10.0 Vulnerability in VeloCloud Orchestrator Exploited via Certificate-Based Authentication
A critical vulnerability (CVSS 10.0) in Arista's VeloCloud Orchestrator allows remote exploitation via certificate-based authentication, with active attacks reported. Patches are available for some versions, but others remain vulnerable, requiring immediate mitigation steps.
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22.
The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are
*** END OF TRANSMISSION ***