AI Weekly Malaysia

Back to items Summaries

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

ID
27263
Status
summarized
Published
22 Sep 2026, 8:29 PM
Fetched
22 Sep 2026, 10:32 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
2.0
Created
22 Sep 2026, 10:38 PM
Tags
Audience
developers

What happened

A CVSS 10.0 vulnerability (CVE-2026-93952) in on-premises VeloCloud Orchestrator (VCO) is being actively exploited, but only affects orchestrators using certificate-based Edge authentication. Arista released fixes for the 5.2 and 6.4 trains on September 22, but 6.1 and 7.0 trains remain unpatched. A compromised VCO could give attackers control over all managed Edge devices.

Why it matters

If your organisation runs on-prem VeloCloud Orchestrator with certificate-based Edge auth, check your release train immediately and upgrade to 5.2.3.16+ or 6.4.2.8+; if you're on 6.1 or 7.0, there is no fix yet and you should restrict network access to the VCO web interface. For everyone else, this is enterprise SD-WAN gear with no direct impact on typical developer or SaaS workflows.

Discussion angle

Brief mention only: how many in the community actually touch on-prem SD-WAN orchestrators, and whether this pattern of 'second critical flaw in the same product in three months' changes procurement decisions for network infrastructure.

Top