## Overview
CISA added CVE-2026-93952 to its Known Exploited Vulnerabilities (KEV) catalog on September 22, 2026. This vulnerability affects the Arista VeloCloud Orchestrator (VCO) on-premise versions. It allows remote attackers to access privileged internal functions, potentially compromising the orchestrator's host.
## Technical Details
The vulnerability stems from improper input validation within the VeloCloud Orchestrator. Attackers can exploit this flaw to gain unauthorized access to sensitive functionalities. The CVSS score of 9.5 indicates a critical level of risk. Both hosted and dedicated versions of VCO are affected. Arista has already released patches for these versions.
## Impact
Successful exploitation of CVE-2026-93952 can lead to severe consequences. Attackers may compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. This could disrupt network operations and expose sensitive information to unauthorized parties.
## Mitigation
Defenders should prioritize applying the latest patches provided by Arista for the VeloCloud Orchestrator. Regularly update systems and monitor for any signs of exploitation. Organizations using affected versions must ensure they address this vulnerability promptly to mitigate potential risks.
CSURFACE Threat Sensor