Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Britain’s far-right violence comes to us direct from the 1970s. But so does the solution | Taj Ali

    September 23, 2026

    Don’t go bananas over tale of chimp rescuing zookeeper

    September 23, 2026

    Ethiopia and Tigray accuse each of launching offensives, fuelling fears of new war

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Britain’s far-right violence comes to us direct from the 1970s. But so does the solution | Taj Ali
    • Don’t go bananas over tale of chimp rescuing zookeeper
    • Ethiopia and Tigray accuse each of launching offensives, fuelling fears of new war
    • UK to join EU ocean science scheme to better predict extreme weather events | Climate crisis
    • Nearly 70% of workers use AI regularly now – but many get no time to upskill
    • Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
    • Raiffeisen Expands Crypto Access With Bitpanda
    • First series of adult T. rex footprints hints at its walking speed
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Arista patches actively exploited VeloCloud Orchestrator zero-day

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 23, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments.

    VCO is a cloud-based centralized management platform that helps admins configure, monitor, and manage VeloCloud SD-WANs (Software-Defined Wide Area Networks) and associated edge devices.

    Tracked as CVE-2026-93952, this maximum-severity flaw stems from an improper input validation weakness and affects VCO deployments where certificate-based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured.

    Remote threat actors can exploit the vulnerability to access privileged internal VCO host functionality in low-complexity attacks that don’t require privileges on the targeted system or user interaction.

    “This issue was discovered externally and is known to be actively exploited,” the company warned in a Tuesday advisory. “Access to the public portion of the VeloCloud Edge authentication certificate is required. A successful attack requires network access to the VCO web interface. VCO tenant or operator credentials are not required for this exposure.”

    Arista says that it has already patched hosted deployments running VCO 5.2.3.16 or later and VCO 6.4.2.8 or later and that it will also release security patches for VCO instances running 6.1.3.7 and below and 7.0.0.2 and below.

    The U.S. Cybersecurity and Infrastructure Security Agency has also added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog on Tuesday and ordered U.S. federal civilian executive branch agencies to secure their networks by Friday, September 25.

    Indicators of compromise

    While security patches are being deployed, admins should restrict access to the VCO web interface to administrative networks, review recent administrator activity for unusual changes, and monitor for connections from known malicious IP addresses.

    Admins should review VCO web access logs for suspicious activity, such as requests containing encoded characters, unusual URL-like path components, references to local or internal services, or high request rates.

    Arista also advised security teams to block the 142[.]93.149.77 and 104[.]248.126.159 IP addresses and review nginx logs for the x-vc-opt HTTP header, and said that unexpected outbound HTTP or HTTPS activity originating from the VCO host may also warrant further review.

    “If compromise is suspected, operators should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible,” it added, and advised customers to contact the Arista Networks Technical Assistance Center (TAC) if they need additional assistance.

    Since the start of the year, Arista patched two other zero-day flaws (CVE-2026-7473 in May and CVE-2026-16812 in July) that were being actively exploited in attacks and affected Extensible Operating System (EOS) and on-premises VeloCloud Orchestrator deployments, respectively.

    Arista Networks is a Fortune 500 company and one of the largest United States corporations by revenue, with more than 10,000 customers worldwide.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    actively Arista Exploited Orchestrator Patches VeloCloud ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

    Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare

    Microsoft: September Windows updates break Always On VPN connections

    D-Link warns of max severity zero-day bug in DIR-822A routers

    F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

    Ryuk ransomware member sentenced to 24 months in prison

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Britain’s far-right violence comes to us direct from the 1970s. But so does the solution | Taj Ali

    September 23, 2026

    Don’t go bananas over tale of chimp rescuing zookeeper

    September 23, 2026

    Ethiopia and Tigray accuse each of launching offensives, fuelling fears of new war

    September 23, 2026

    UK to join EU ocean science scheme to better predict extreme weather events | Climate crisis

    September 23, 2026
    Latest Posts

    Ransom Cartel ransomware creator sentenced to 16 years in prison

    August 5, 2026

    Uber CEO brushes off reports of a Waymo break-up

    August 5, 2026

    Fauci Faces Contempt Vote. Here Are the Legal Issues Involved.

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Britain’s far-right violence comes to us direct from the 1970s. But so does the solution | Taj Ali

    September 23, 2026

    Don’t go bananas over tale of chimp rescuing zookeeper

    September 23, 2026

    Ethiopia and Tigray accuse each of launching offensives, fuelling fears of new war

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.