CVE-2026-93952
📛 CVE Title
Security Advisory 0183
Description
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Arista
- CVSS severity
- CRITICAL
- CVSS score
- 9.5 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H- Effective score
- 9.5 / 10 CRITICAL source: CNA overview
- CWE(s)
-
CWE-20 - Reserved
- 2026-09-19
- Published
- 2026-09-22 07:37 UTC
- Last updated
- 2026-09-22 19:58 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93952.json
- Linked Threat
- CVE-2026-93952 — Arista VeloCloud Orchestrator: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
CISA Known Exploited Vulnerabilities CISA KEV
CISA has confirmed in-the-wild exploitation of this CVE. Federal agencies must remediate by the due date below; private orgs should treat it as priority-1.
- Vulnerability name
- Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Vendor / project
- Arista
- Product
- VeloCloud Orchestrator
- Date added to KEV
- 2026-09-22
- Remediation due
- 2026-09-25
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Ransomware campaign use
- Unknown
- CISA notes
- https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183 ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-93952
- CISA listing
- www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-22 08:16:43 UTC
- NVD last modified
- 2026-09-22 20:17:12 UTC
- NVD CVSS v3.1
- 10.0 / 10 CRITICAL source: psirt@arista.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 6.0 / 10
- EPSS score
- 0.0042 (probability of exploitation in next 30 days)
- EPSS percentile
- 36.32% vs all CVEs — higher = more likely to be exploited, as of 2026-09-22
NVD / KEV / EPSS data refreshed 2026-09-23 02:32 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-84296 - Assigner
- Arista
- Published
- Sep 22, 2026, 7:37:24 AM
- Updated
- Sep 23, 2026, 3:55:40 AM
- EUVD base score (CVSS 4.0)
-
9.5 / 10
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H - EUVD-reported EPSS
- 0.4200
- Vendors
- Arista Networks
- Products
-
VeloCloud Orchestrator (VCO) On-Prem (6.1.0 ≤6.1.3.7)VeloCloud Orchestrator (VCO) On-Prem (5.2.0 ≤5.2.3.15)VeloCloud Orchestrator (VCO) On-Prem (6.4.0 ≤6.4.2.7)VeloCloud Orchestrator (VCO) On-Prem (7.0.0 ≤7.0.0.2)
- Aliases
-
GHSA-fqhw-f6hf-cq3w
ENISA description: VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Arista Networks | VeloCloud Orchestrator (VCO) On-Prem |
5.2.0 (affected),
6.1.0 (affected),
6.4.0 (affected),
7.0.0 (affected)
|
VeloCloud Orchestrator On-Prem |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- Security Advisory 0183 vendor-advisory
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (2)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183 psirt@arista.com
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93952 134c704f-9b21-4f2e-91b3-4a467353bcc0
Indicators (2)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| cwe |
CWE-20
|
no local data | 2026-09-23 02:57 UTC |
| cve |
CVE-2026-93952
|
no local data | 2026-09-23 02:57 UTC |
Remediations (1)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
CISA KEV
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due date: 2026-09-25 Known ransomware campaign use: Unknown
2026-09-23 02:15 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-93952.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93952",
"options": [
{
"Exploitation": "active"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T19:40:04.719145Z",
"version": "2.0.3"
},
"type": "ssvc"
}
},
{
"other": {
"content": {
"dateAdded": "2026-09-22",
"reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93952"
},
"type": "kev"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T19:58:23.492Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"government-resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93952"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-22T00:00:00.000Z",
"value": "CVE-2026-93952 added to CISA KEV"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"VeloCloud Orchestrator On-Prem"
],
"product": "VeloCloud Orchestrator (VCO) On-Prem",
"vendor": "Arista Networks",
"versions": [
{
"lessThanOrEqual": "5.2.3.15",
"status": "affected",
"version": "5.2.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "6.1.3.7",
"status": "affected",
"version": "6.1.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "6.4.2.7",
"status": "affected",
"version": "6.4.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "7.0.0.2",
"status": "affected",
"version": "7.0.0",
"versionType": "custom"
}
]
}
],
"configurations": [
{
"lang": "en",
"value": "VCO is exposed if certificate based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured. Access to the public portion of the VeloCloud Edge authentication certificate is required. A successful attack requires network access to the VCO web interface. VCO tenant or operator credentials are not required for this exposure.\n\nDeployments that restrict VCO web interface access to trusted administrative networks can reduce risk of exposure."
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.</p><p>Hosted, including Dedicated, versions of VCO were impacted and have already been patched.</p>"
}
],
"value": "VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.\n\nHosted, including Dedicated, versions of VCO were impacted and have already been patched."
}
],
"impacts": [
{
"capecId": "CAPEC-115",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-115 Authentication Bypass"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 10,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 9.5,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20 Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T07:37:24.300Z",
"orgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"shortName": "Arista"
},
"references": [
{
"name": "Security Advisory 0183",
"tags": [
"vendor-advisory"
],
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183"
}
],
"solutions": [
{
"lang": "en",
"value": "The recommended resolution is to upgrade to a remediated VCO software version at your earliest convenience. These vulnerabilities have been fixed in the following releases:\n- VCO 5.2.3.16 and later in the 5.2.3 train\n- VCO 6.4.2.8 and later in the 6.4.2 train\n\nReleases in other release trains that fix this will be added over time. For VCOs not on a supported release train, customers can contact TAC to discuss possible upgrade options."
}
],
"source": {
"advisory": "Security Advisory 0183",
"defect": [
"BUG1907167",
"BUG1937417"
],
"discovery": "EXTERNAL"
},
"title": "Security Advisory 0183",
"workarounds": [
{
"lang": "en",
"value": "Until fixed software is deployed, operators should apply defense-in-depth controls appropriate for their environment:\n- Restrict access to the VCO web interface to trusted administrative networks.\n- Monitor the VCO for accesses from known malicious source IPs.\n- Monitor for unexpected outbound network activity from the VCO host.\n- Consider blocking outbound ports not needed for normal activities.\n- Monitor for backdoor daemons and webshells.\n- Review recent administrator activity for unexpected changes."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"assignerShortName": "Arista",
"cveId": "CVE-2026-93952",
"datePublished": "2026-09-22T07:37:24.300Z",
"dateReserved": "2026-09-19T01:37:47.225Z",
"dateUpdated": "2026-09-22T19:58:23.492Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}