bleeping-computer · Crawled Sep 23, 2026
Arista patches actively exploited VeloCloud Orchestrator zero-day
3 IoCs
Read original article ↗
AI Summary
Arista Networks has patched a zero-day vulnerability, tracked as CVE-2026-93952, in its VeloCloud Orchestrator (VCO) On-Prem deployments that was actively exploited in the wild. The flaw stems from improper input validation and allows remote unauthenticated attackers to access privileged internal functionality by exploiting certificate-based authentication mechanisms. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities catalog, requiring federal agencies to remediate by September 25, 2026.
AI-extracted · verify before operational use