Arista Urges Immediate Patching of Exploited VCO Zero-Day

Arista Urges Immediate Patching of Exploited VCO Zero-Day
Arista has issued urgent fixes for CVE-2026-93952, a critical zero-day in on-premises VeloCloud Orchestrator deployments that could let remote attackers reach privileged internal functions. The flaw affects VeloCloud Orchestrator On-Prem and has been added to CISA’s Known Exploited Vulnerabilities list, with admins urged to patch and review logs immediately. #Arista #VeloCloudOrchestrator #CVE202693952 #CISA

Keypoints

  • Arista released urgent patches for a critical VeloCloud Orchestrator zero-day.
  • The vulnerability is tracked as CVE-2026-93952 and has been actively exploited.
  • Successful attacks could affect the orchestrator’s confidentiality, integrity, and availability.
  • The issue impacts only VeloCloud Orchestrator On-Prem deployments.
  • Administrators should update immediately and check logs for suspicious activity.

Read More: https://www.securityweek.com/arista-urges-immediate-patching-of-exploited-vco-zero-day/