Exploited in the wild VeloCloud Orchestrator network-edge Arista zero-day
Arista Urges Immediate Patching of Exploited VCO Zero-Day
CVE Tools coverage
Arista has released emergency fixes for CVE-2026-93952, a CVSS 10 improper input validation flaw actively exploited against on-premises VeloCloud Orchestrator deployments. The issue can let a remote attacker reach privileged internal functions, potentially compromising the confidentiality, integrity, and availability of the orchestrator and its managed data. Arista fixed the affected 5.2.x and 6.1.x trains in VCO versions 5.2.3.16 and 6.4.2.8, respectively, and advises organizations to update immediately.