s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2026-93952

📛 CVE Title

Security Advisory 0183

Description

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

Overview

State
PUBLISHED
Assigner (CNA)
Arista
CVSS severity
CRITICAL
CVSS score
CVSS 9.5 / 10 9.5 9.5 / 10
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Effective score
9.5 / 10 CRITICAL source: CNA overview
CWE(s)
CWE-20
Reserved
2026-09-19
Published
2026-09-22 07:37 UTC
Last updated
2026-09-22 19:58 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93952.json
Linked Threat
CVE-2026-93952 — Arista VeloCloud Orchestrator: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

CISA Known Exploited Vulnerabilities CISA KEV

CISA has confirmed in-the-wild exploitation of this CVE. Federal agencies must remediate by the due date below; private orgs should treat it as priority-1.

Vulnerability name
Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
Vendor / project
Arista
Product
VeloCloud Orchestrator
Date added to KEV
2026-09-22
Remediation due
2026-09-25
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Ransomware campaign use
Unknown
CISA notes
https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183 ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-93952
CISA listing
www.cisa.gov/known-exploited-vulnerabilities-catalog

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-09-22 08:16:43 UTC
NVD last modified
2026-09-22 20:17:12 UTC
NVD CVSS v3.1
CVSS 10.0 / 10 10.0 10.0 / 10 CRITICAL source: psirt@arista.com
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability subscore
3.9 / 10
Impact subscore
6.0 / 10
EPSS score
0.0042 (probability of exploitation in next 30 days)
EPSS percentile
36.32% vs all CVEs — higher = more likely to be exploited, as of 2026-09-22

NVD / KEV / EPSS data refreshed 2026-09-23 02:32 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-84296
Assigner
Arista
Published
Sep 22, 2026, 7:37:24 AM
Updated
Sep 23, 2026, 3:55:40 AM
EUVD base score (CVSS 4.0)
9.5 / 10
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EUVD-reported EPSS
0.4200
Vendors
Arista Networks
Products
VeloCloud Orchestrator (VCO) On-Prem (6.1.0 ≤6.1.3.7)
VeloCloud Orchestrator (VCO) On-Prem (5.2.0 ≤5.2.3.15)
VeloCloud Orchestrator (VCO) On-Prem (6.4.0 ≤6.4.2.7)
VeloCloud Orchestrator (VCO) On-Prem (7.0.0 ≤7.0.0.2)
Aliases
GHSA-fqhw-f6hf-cq3w

ENISA description: VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

EUVD references (1)

Affected products (1)

VendorProductVersionsPlatforms
Arista Networks VeloCloud Orchestrator (VCO) On-Prem 5.2.0 (affected), 6.1.0 (affected), 6.4.0 (affected), 7.0.0 (affected) VeloCloud Orchestrator On-Prem

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

NVD-tagged references (2)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Indicators (2)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
cwe CWE-20 no local data 2026-09-23 02:57 UTC
cve CVE-2026-93952 no local data 2026-09-23 02:57 UTC

Flagged vendors

    Remediations (1)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • CISA KEV

      Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due date: 2026-09-25 Known ransomware campaign use: Unknown

      2026-09-23 02:15 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2026-93952.json.

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93952",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T19:40:04.719145Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-09-22",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93952"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T19:58:23.492Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93952"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-09-22T00:00:00.000Z",
                "value": "CVE-2026-93952 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "VeloCloud Orchestrator On-Prem"
              ],
              "product": "VeloCloud Orchestrator (VCO) On-Prem",
              "vendor": "Arista Networks",
              "versions": [
                {
                  "lessThanOrEqual": "5.2.3.15",
                  "status": "affected",
                  "version": "5.2.0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "6.1.3.7",
                  "status": "affected",
                  "version": "6.1.0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "6.4.2.7",
                  "status": "affected",
                  "version": "6.4.0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "7.0.0.2",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "value": "VCO is exposed if certificate based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured. Access to the public portion of the VeloCloud Edge authentication certificate is required. A successful attack requires network access to the VCO web interface. VCO tenant or operator credentials are not required for this exposure.\n\nDeployments that restrict VCO web interface access to trusted administrative networks can reduce risk of exposure."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "<p>VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.</p><p>Hosted, including Dedicated, versions of VCO were impacted and have already been patched.</p>"
                }
              ],
              "value": "VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.\n\nHosted, including Dedicated, versions of VCO were impacted and have already been patched."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-115",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-115 Authentication Bypass"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 10,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "baseScore": 9.5,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T07:37:24.300Z",
            "orgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
            "shortName": "Arista"
          },
          "references": [
            {
              "name": "Security Advisory 0183",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "The recommended resolution is to upgrade to a remediated VCO software version at your earliest convenience. These vulnerabilities have been fixed in the following releases:\n- VCO 5.2.3.16 and later in the 5.2.3 train\n- VCO 6.4.2.8 and later in the 6.4.2 train\n\nReleases in other release trains that fix this will be added over time. For VCOs not on a supported release train, customers can contact TAC to discuss possible upgrade options."
            }
          ],
          "source": {
            "advisory": "Security Advisory 0183",
            "defect": [
              "BUG1907167",
              "BUG1937417"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Security Advisory 0183",
          "workarounds": [
            {
              "lang": "en",
              "value": "Until fixed software is deployed, operators should apply defense-in-depth controls appropriate for their environment:\n- Restrict access to the VCO web interface to trusted administrative networks.\n- Monitor the VCO for accesses from known malicious source IPs.\n- Monitor for unexpected outbound network activity from the VCO host.\n- Consider blocking outbound ports not needed for normal activities.\n- Monitor for backdoor daemons and webshells.\n- Review recent administrator activity for unexpected changes."
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
        "assignerShortName": "Arista",
        "cveId": "CVE-2026-93952",
        "datePublished": "2026-09-22T07:37:24.300Z",
        "dateReserved": "2026-09-19T01:37:47.225Z",
        "dateUpdated": "2026-09-22T19:58:23.492Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }