CVE-2026-93952 actively exploited: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

CISA added CVE-2026-93952, an improper input validation in Arista VeloCloud Orchestrator, to its Known Exploited Vulnerabilities catalogue. It may allow a remote attacker to access privileged internal functionality and impact the VCO host. Federal agencies must remediate by September 25, 2026.

Cover image for CVE-2026-93952 actively exploited: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

A flaw in Arista VeloCloud Orchestrator allows remote intruders to bypass standard security checks. This improper input validation enables exploitation of privileged internal features. Such access threatens the stability of the underlying host system. Attackers could compromise the confidentiality and integrity of managed data. The source notes that specific ransomware groups have not been confirmed to use this defect. The CISA registry flags this issue as actively exploited in the wild. Administrators operating the on-premises version of the orchestrator face the highest risk. Any deployment exposing the platform to external networks remains vulnerable. The vulnerability impacts the core functionality of the management software. It also jeopardizes the data structures maintained by the system. Organizations using third-party provider instances for this software hold distinct responsibilities. These groups must verify their providers adhere to strict patching protocols. Internal cloud services may also face similar compliance pressures. Evaluating internet exposure for every connected asset is critical. Vendors must install updates following specific manufacturer instructions promptly. Teams should verify that systems meet requirements outlined in CISA BOD 26-04. This directive prioritizes security updates based on measured risk levels. Forensic triage steps must be executed as described by CISA. If no patch exists, operators should stop using the product entirely. Direct internet access to this software increases potential damage significantly. Compliance deadlines for federal entities end on September 25, 2026. Other organizations should treat this date as a strong benchmark. Monitoring network traffic for unusual privileged access remains advisable during remediation.