Skip to content

CVE-2026-93952 explained: what the Arista VeloCloud Orchestrator flaw means for your business

By Donovan Brown
September 23, 2026
8 sections
CVE-2026-93952 explained: what the Arista VeloCloud Orchestrator flaw means for your business — Cyber Security article cover card from LayerLogix, with a warning alert icon
01

Introduction

CVE-2026-93952 is a critical security flaw in Arista VeloCloud Orchestrator (VCO), the software many businesses use to manage their wide-area network. Attackers are already using it in the wild. If your business runs VeloCloud Orchestrator on-prem, keep reading closely. If you don't run this software at all, you can skip most of this.

02

Does this affect you?

The two-minute check

  1. Open the VeloCloud Orchestrator login screen or admin dashboard on the computer, phone or server you run it on.
  2. Look for a version number, usually shown near the login page or inside a settings menu.
  3. Check whether your deployment is on-prem, hosted, or dedicated. Ask your network team if you are unsure.
  4. Note whether the orchestrator's management interface is reachable from the open internet.
  5. Write down what you find so you can share it with whoever manages your network.

When you can stop reading

The record names only Arista VeloCloud Orchestrator. If your business does not run this software, this flaw does not apply to you. The advisory also states that hosted and dedicated versions of VCO were already patched. If your orchestrator is hosted or dedicated, rather than on-prem, you can close this tab.

03

How bad is it, honestly?

What the official record says

The National Vulnerability Database (NVD) scores this flaw a perfect 10 out of 10, rated CRITICAL, on the Common Vulnerability Scoring System (CVSS) version 3.1 (NVD).

The scoring vector shows an attacker only needs network access. No special skill is required, and no login is needed at all. Nobody at your business has to click a link or open a file for this to work.

This flaw sits on the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog, added on 2026-09-22. That listing means criminals are already using this flaw, not just that it is theoretically dangerous (CISA KEV). The same catalog entry does not currently flag confirmed ransomware use tied to this flaw.

The Exploit Prediction Scoring System (EPSS) puts the probability of exploitation in the next 30 days at 0.42%, in the 36th percentile of all scored flaws (FIRST.org). That is a low chance of exploitation in the next 30 days. EPSS forecasts near-term exploitation activity. It does not measure how severe the flaw itself is.

What that means for a business like yours

A perfect CVSS score paired with active exploitation is a serious combination, even with a low EPSS forecast. The record says a successful attack can expose confidentiality, integrity, and availability of the orchestrator and the data it manages. In plain terms, an attacker could read your network configuration, change it, or knock it offline. For a business that depends on that network for daily operations, any of those outcomes causes real disruption.

04

What to do about it, step by step

If someone else manages your IT

Send this to your provider. Keep it short.

"Are we running Arista VeloCloud Orchestrator on-prem?" "Is its management interface reachable from the public internet?" "What are we doing about CVE-2026-93952 until Arista ships a fix?"

If you manage it yourself

  1. Confirm whether your VeloCloud Orchestrator deployment is on-prem, not hosted or dedicated.
  2. Check your firewall rules for the orchestrator's management interface.
  3. Restrict access to that interface to a small, known list of internal IP addresses.
  4. Turn off remote management access entirely if your business does not need it.
  5. Read Arista's advisory in full before making any configuration changes (Arista advisory).
  6. Watch that same advisory page for a fixed version, since the record does not name one yet.
05

How long you have

The answer is now. This flaw is already on the CISA Known Exploited Vulnerabilities (KEV) catalog, with a federal remediation due date of 2026-09-25 (CISA KEV). That deadline applies to federal agencies. It still tells you attackers are actively scanning for this weakness today, not next month.

06

How to check it actually worked

There is no patched version listed on the record yet, so there is nothing to install and verify today. What you can verify right now is your exposure. Confirm your orchestrator's management interface is no longer reachable from the open internet. Test this from outside your network, not just from inside your office. Re-check Arista's advisory page regularly for a version number. Once a fix ships, confirm that exact version appears on your own login screen before you consider the job done.

07

What to do if you can't patch right now

Since no fixed version exists yet, every business running this software is in the same position. Restricting network access to the orchestrator's management interface is your strongest interim step. This does not remove the flaw. It does shrink who can reach it from outside your network. Pair that with close monitoring of your orchestrator's logs for unexpected administrative activity. Multi-factor authentication (MFA) on related management accounts adds another layer of protection. It will not stop this specific attack, since the scoring vector shows no login is required at all. A layered approach to cybersecurity, including tighter privileged access controls, reduces your exposure while you wait for a vendor fix.

08

Frequently Asked Questions

Do I have to do anything if we only use this at home?

VeloCloud Orchestrator is business networking software, not a home product. If your household does not run it, this record does not apply to you.

Will restricting access break anything for our team?

Limiting who can reach the management interface should not affect normal network traffic. It only narrows who can log into the orchestrator's administrative functions.

Does this affect our other business software?

The record names only Arista VeloCloud Orchestrator. It does not mention any other product, so there is no reason to assume anything else is affected.

Are we legally required to fix this by the CISA deadline?

The 2026-09-25 due date applies to federal agencies. Your business is not legally bound by it, but the same urgency applies since criminals are already exploiting this flaw.

What if we're not sure whether our deployment is on-prem or hosted?

Ask whoever set up your network, or check your service contract with Arista. If your business handles regulated data, this is also worth reviewing alongside your HIPAA or FTC Safeguards Rule obligations.

If you want a second set of eyes on your network exposure, LayerLogix offers a free IT assessment, backed by 20+ years of experience and 100% Texas-based support. Our managed IT services team can track this advisory for you. Contact us to talk through your specific setup.

Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call