New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Arista Networks says attackers are actively exploiting CVE-2026-93952, a CVSS 10.0 vulnerability in on-premises VeloCloud Orchestrator deployments using certificate-based Edge authentication. A remote unauthenticated attacker with network access to the VCO web interface and an Edge certificate's public portion could access privileged internal functions, compromise the orchestrator, and potentially reach managed Edge devices. Fixed releases are available for 5.2 and 6.4, while fixes for affected 6.1 and 7.0 releases are pending; organizations should restrict VCO web access and monitor for signs of compromise.