What happened

CISA's September 22 alert added four entries to the KEV catalog: F5 BIG-IP APM, two Check Point flaws (covered in our F5 and Check Point post) and this one, listed as "Arista VeloCloud Orchestrator Improper Input Validation Vulnerability."

Arista's advisory says the flaw "may allow a remote attacker to access privileged internal functionality and impact the VCO host," compromising "the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator." It "was discovered externally and is known to be actively exploited." Arista does not say when exploitation started or who is behind it, and public reporting has not added either.

There is an important precondition. According to The Hacker News' reading of the advisory, only orchestrators where "certificate based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured" are affected, and the attacker needs network access to the VCO web interface plus the public part of an Edge's authentication certificate. Public certificate material is, by design, not secret.

Affected and fixed versions

TrainAffectedFixed
5.2.x5.2.3.15 and below5.2.3.16 and later
6.1.x6.1.3.7 and belowNo fixed release listed yet
6.4.x6.4.2.7 and below6.4.2.8 and later
7.0.x7.0.0.2 and belowNo fixed release listed yet

Arista's resolution section reads: "Releases in other release trains that fix this will be added over time." At least one security vendor's write-up says fixes are available for the 6.1 and 7.0 branches as well; we could not confirm that against Arista's advisory, so check the advisory itself before planning an upgrade on those trains. Hosted and Dedicated VCO instances were affected and "have already been patched."

Indicators of compromise

Arista lists these indicators:

  • Files: /usr/local/sbin/.vcnode.js, /usr/local/sbin/vc-sysmond, /etc/systemd/system/vc-sysmon.service
  • MD5: dc78e206eaeadec59fc5801fe4556bd0
  • HTTP header in requests: x-vc-opt
  • IP addresses: 142.93.149[.]77, 104.248.126[.]159

Why it matters if you run public infrastructure

The orchestrator is the control plane for every SD-WAN Edge in the estate: branch routing, tunnels, firewall rules. Edges in branch offices have to reach it, so an on-premises VCO is often reachable from the internet by design. That makes it the same class of target as the firewall managers exploited earlier this month (see Cisco FMC): one server whose compromise hands over the network it manages. With two release trains still waiting for a fix, restricting access is the only control some operators have.

What to check this week

  1. Check your VCO version and whether Edge certificate authentication is enabled. If you run 5.2.3 or 6.4.2, upgrade to 5.2.3.16 or 6.4.2.8 or later now.
  2. If you run 6.1.x or 7.0.x, follow Arista's advisory for the fixed release, and until then restrict the VCO web interface to trusted administrative networks, as Arista recommends. Edges need to reach the orchestrator; administrators browsing from anywhere do not.
  3. Hunt for the indicators above: the three files and the systemd unit, the hash, requests carrying an x-vc-opt header in web logs, and traffic to or from the two IP addresses.
  4. Review the orchestrator for changes you did not make: new administrators, configuration pushes to Edges, unexpected outbound connections, as Arista's mitigation guidance suggests.
  5. If you use hosted VCO, there is nothing to patch, but reviewing recent administrative activity is still worthwhile.

How Attack Surface Scan covers this

Partially. VeloCloud Orchestrator is not in the product catalog our vulnerability matching recognizes, so we will not raise a CVE finding for CVE-2026-93952 or read the VCO version. What we do show is exposure: if your orchestrator has a hostname under your verified domains (or one we find in certificate transparency logs), we record that it answers on 443 or another web port we check (see Exposed services), the certificate it presents, and alert you when a new login page or listener appears. That answers "is our orchestrator's web interface on the internet"; whether it is patched, and whether certificate authentication is on, has to be checked on the VCO. We never test the exploit. See Vulnerability matching for the products we do match.

Sources