New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
- ID
- 27263
- Status
- summarized
- Published
- 22 Sep 2026, 8:29 PM
- Fetched
- 22 Sep 2026, 10:32 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.0
- Created
- 22 Sep 2026, 10:38 PM
- Tags
- Audience
- developers
What happened
A CVSS 10.0 vulnerability (CVE-2026-93952) in on-premises VeloCloud Orchestrator (VCO) is being actively exploited, but only affects orchestrators using certificate-based Edge authentication. Arista released fixes for the 5.2 and 6.4 trains on September 22, but 6.1 and 7.0 trains remain unpatched. A compromised VCO could give attackers control over all managed Edge devices.
Why it matters
If your organisation runs on-prem VeloCloud Orchestrator with certificate-based Edge auth, check your release train immediately and upgrade to 5.2.3.16+ or 6.4.2.8+; if you're on 6.1 or 7.0, there is no fix yet and you should restrict network access to the VCO web interface. For everyone else, this is enterprise SD-WAN gear with no direct impact on typical developer or SaaS workflows.
Discussion angle
Brief mention only: how many in the community actually touch on-prem SD-WAN orchestrators, and whether this pattern of 'second critical flaw in the same product in three months' changes procurement decisions for network infrastructure.