Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
About this summary. This is a short, independently written summary of an article first published by The Hacker News. Cyber Security News did not report or verify the underlying story. Read the original: https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html

Source attribution: headline and facts are from The Hacker News (thehackernews.com). Summary method: excerpt of the source description. See our source attribution policy.


