Threat Intelligence

Critical Flaw in VeloCloud SD-WAN Management Server Under Active Attack

The Hacker News · 22 Sept 2026
Key Takeaway If your business uses VeloCloud SD-WAN with certificate-based Edge authentication, check Arista's advisory now and apply the latest patch or mitigation steps immediately.

Arista disclosed on September 22 that attackers are actively exploiting a critical flaw, tracked as CVE-2026-93952, in on-premises VeloCloud Orchestrator (VCO). VCO is the server that manages Edge devices in a VeloCloud SD-WAN network. The flaw carries the maximum CVSS severity score of 10.0 and could let a remote attacker with no login credentials gain privileged access to the orchestrator, potentially compromising the device and any Edge devices it manages.

The flaw only affects orchestrators configured to authenticate their Edge devices using certificates, rather than the pre-shared key option. An attacker would also need network access to the VCO web interface and a copy of an Edge's authentication certificate to exploit it. This is a separate issue from another VCO flaw Arista reported as exploited back in July, which affected all setups by default regardless of configuration.

Fixed software releases are currently available for the 5.2 and 6.4 release trains, with patches for the 6.1 and 7.0 trains still in development. Arista has already patched its Hosted and Dedicated VCO versions. Customers running unsupported release trains are advised to contact Arista's Technical Assistance Center about upgrade paths, and Arista has published interim mitigation steps for those unable to patch immediately.

VeloCloud SD-WAN vulnerability Arista critical patch

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.