Attackers are actively exploiting a critical vulnerability in on-premises VeloCloud Orchestrator systems that Arista rated with a perfect 10.0 severity score, the company disclosed on September 22. The flaw, designated CVE-2026-93952, lets remote attackers without login credentials gain access to privileged internal functions and compromise the orchestrator host that manages Edge devices in a VeloCloud SD-WAN deployment. Arista said the vulnerability "was discovered externally and is known to be actively exploited," though the company did not reveal when attacks started or how many systems have been compromised.

Only orchestrators configured to authenticate their Edge devices using certificates are vulnerable to the flaw. The vulnerability affects multiple release trains, including version 5.2.3.15 and earlier, 6.1.3.7 and earlier, 6.4.2.7 and earlier, and 7.0.0.2 and earlier. As of September 22, patches are available for the 5.2 and 6.4 trains in versions 5.2.3.16 and 6.4.2.8 respectively, but fixes for the 6.1 and 7.0 trains are not yet released. The affected versions include those that patched a separate VCO vulnerability that Arista reported as exploited in July. An attacker needs network access to the VCO web interface and the public portion of an Edge device's authentication certificate to carry out an attack. Arista has already deployed fixes for its Hosted and Dedicated VCO versions.

A successful compromise may give attackers control of the orchestrator and all data it handles, according to Arista. The company warns that a breached orchestrator can also provide attackers with access to the Edge devices it controls. Arista recommends customers who cannot immediately upgrade should restrict access to the VCO web interface to trusted administrative networks, watch for connections from known malicious IP addresses, and monitor for unusual outbound traffic from the orchestrator host. The company also advises watching for backdoor daemons and webshells, and reviewing recent administrator actions for suspicious changes.

The severity reflects how SD-WAN orchestrators serve as central control points for distributed network infrastructure, making them high-value targets. Unlike the July vulnerability, which exposed all VCO systems by default regardless of configuration, this flaw only affects deployments using certificate-based authentication—but those systems face total compromise if exploited. Organizations that find indicators of breach should preserve the orchestrator's state and save web access logs, backend application logs, system logs, database logs, and file-system timestamps before attempting remediation, where practical. Arista recommends incident response steps after upgrading, including rotating credentials, reviewing administrator activity, checking the condition of managed Edge devices, and restoring or replacing the orchestrator from verified sources. The timing is particularly concerning given that many affected versions were already patched for the previous exploited flaw just two months ago, suggesting attackers are aggressively targeting this platform. Organizations running infrastructure this critical may need to reconsider how quickly they can deploy emergency patches when a vendor signals active exploitation, especially for systems that bridge cloud and on-premises networks.