Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5511 articles · 220897 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2026-93952KEVEXPLOITEDPATCHED
arista · velocloud orchestrator (vco) on-prem

Security Advisory 0183

Description

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

Affected Products

VendorProductVersions
aristavelocloud orchestrator (vco) on-prem5.2.0, 6.1.0, 6.4.0, 7.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
aristavelocloud orchestratorcert_advisory90%

References

  • https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183(vendor-advisory)

Related News (4 articles)

Tier B
CCCS Canada5h ago
Arista Networks security advisory (AV26-947)
→ No new info (linked only)
Tier D
The Hacker News5h ago
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
→ No new info (linked only)
Tier B
BSI Advisories6h ago
[NEU] [hoch] Arista VeloCloud Orchestrator: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
→ No new info (linked only)
Tier C
VulDB10h ago
CVE-2026-93952 | Arista VeloCloud Orchestrator On-Prem up to 5.2.3.15/6.1.3.7/6.4.2.7/7.0.0.2 input validation
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
CWECWE-20
PublishedSep 22, 2026
Trending Score130🔥
Source articles4
Independent4
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-73458
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rou
Trending: 24
CRITICALCVE-2026-73456
Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.
Trending: 23
CRITICALCVE-2026-73453
Security Advisory 0174
Trending: 22
MEDIUMCVE-2026-19641
On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legit
Trending: 22
HIGHCVE-2026-73435
Security Advisory 0171
Trending: 21

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 22, 2026
Added to CISA KEV
Sep 22, 2026
Discovered by ZDM
Sep 22, 2026
Actively Exploited
Sep 22, 2026
Patch Available
Sep 22, 2026