A CVSS 10.0 flaw in Arista's on-premises VeloCloud Orchestrator is under attack in certificate-based deployments, and fixes are not yet available for every release train.
Arista disclosed on September 22 that attackers are actively exploiting a new, maximum severity flaw, CVE-2026-93952, CVSS 10.0, in its on-premises VeloCloud Orchestrator, the management server for VeloCloud SD-WAN Edge devices. The flaw affects orchestrators configured to authenticate Edge devices with certificates and lets a remote, unauthenticated attacker with network access to the orchestrator's web interface and the public part of an Edge's certificate reach privileged internal functions.
A successful attack can compromise the orchestrator and the Edge devices it manages, along with the data both hold. Arista has shipped fixes for the 5.2 and 6.4 release trains, and its hosted and dedicated VCO versions are already patched, but fixes for the 6.1 and 7.0 trains are not yet out. Until a patch is applied, Arista recommends limiting access to the orchestrator's web interface to trusted administrative networks.
Why it matters: SD-WAN orchestrators sit at the center of enterprise network and cloud connectivity, so a maximum severity flaw under active exploitation puts every site an edge serves at risk. Timely patching and tight access controls on management infrastructure are core parts of the security operations we run for clients.