{"id":3057,"date":"2026-09-22T15:01:53","date_gmt":"2026-09-22T15:01:53","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3057"},"modified":"2026-09-22T15:01:53","modified_gmt":"2026-09-22T15:01:53","slug":"new-cvss-10-0-velocloud-orchestrator-flaw-actively-exploited-in-certificate-based-setups","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3057","title":{"rendered":"New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Swati Khandelwal<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 22, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Network Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhN5Up_REU7_SnA-Ce9D8UGRsM8WbkkcjR6kjirzb-tSFejrL-qnZkXrp2gNa3OA-4PgvkUqHs59j9Qc8srbfm2JOUIOvEa1c_d8Il3kUDAGyr49FuXwq_n438Vf9txfq1fVwcpykkZAKz1o2QFGUJDLF4wnXzNWLdH1tYft3bd-vJywPppGjEfoikG22s\/s1700-nu-rw-lo-l85-e365\/VeloCloud.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22.<\/p>\n<p>The flaw, tracked as <b>CVE-2026-93952<\/b>, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are exposed.<\/p>\n<p>As of September 22, <a href=\"https:\/\/www.arista.com\/en\/support\/advisories-notices\/security-advisory\/24765-security-advisory-0183\" target=\"_blank\">fixed releases<\/a> are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains. Arista has already patched the Hosted and Dedicated versions of VCO. The affected releases include those that fixed a different VCO flaw, which Arista reported as exploited in July.<\/p>\n<p>Arista gave the flaw a CVSS 3.1 score of 10.0. A successful attack may compromise the orchestrator and the data it manages. A compromised VCO may also give attackers access to the Edge devices it manages.<\/p>\n<p>Arista said the flaw \u00abwas discovered externally and is known to be actively exploited.\u00bb It did not say when the attacks began or how widespread they are. The Hacker News has contacted Arista for comment.<\/p>\n<h3 style=\"text-align: left;\">Which Deployments Are Exposed<\/h3>\n<p>VeloCloud Edges can authenticate to the orchestrator in one of <a href=\"https:\/\/www.arista.com\/en\/admin-guide-vc-7-0\/sd-wan-7-0-provision-a-new-edge\" target=\"_blank\">three modes<\/a>. In Certificate Deactivated mode, an Edge uses a pre-shared key (PSK). In Certificate Acquire and Certificate Required modes, it uses a certificate issued by the orchestrator.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Arista said an orchestrator is exposed if \u00abcertificate based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured.\u00bb It did not say which of those modes meets that condition. The attacker also needs network access to the VCO web interface and the public part of an Edge&#8217;s authentication certificate.<\/p>\n<p>The July flaw did not depend on settings: VCO was exposed to it by default, and no configuration could prevent that.<\/p>\n<p><a name=\"more\"\/><\/p>\n<h3>Fixed Releases<\/h3>\n<p>As of September 22, these are the affected releases in each train, the releases that fix them, and the releases that fixed the July flaw:<\/p>\n<table style=\"border-collapse: collapse; border: 1px solid rgb(217, 217, 217); width: 100%;\">\n<tbody>\n<tr>\n<th scope=\"col\" style=\"border: 1px solid rgb(217, 217, 217); padding: 10px; text-align: left;\">\n        Train\n      <\/th>\n<th scope=\"col\" style=\"border: 1px solid rgb(217, 217, 217); padding: 10px; text-align: left;\">\n        Affected by CVE-2026-93952\n      <\/th>\n<th scope=\"col\" style=\"border: 1px solid rgb(217, 217, 217); padding: 10px; text-align: left;\">\n        Fixed in\n      <\/th>\n<th scope=\"col\" style=\"border: 1px solid rgb(217, 217, 217); padding: 10px; text-align: left;\">\n        July flaw (CVE-2026-16812) fixed in\n      <\/th>\n<\/tr>\n<tr>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        5.2\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        5.2.3.15 and earlier\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        5.2.3.16 and later\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        5.2.3.14\n      <\/td>\n<\/tr>\n<tr>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        6.1\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        6.1.3.7 and earlier\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        No fix yet\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        6.1.3.4\n      <\/td>\n<\/tr>\n<tr>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        6.4\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        6.4.2.7 and earlier\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        6.4.2.8 and later\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        6.4.2.4\n      <\/td>\n<\/tr>\n<tr>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        7.0\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        7.0.0.2 and earlier\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        No fix yet\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        No fix listed. 7.0.0.1 and later were not affected.\n      <\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Arista said fixes for affected trains that are still supported are coming and will be added to its advisory when ready. Customers on an unsupported release train can contact Arista&#8217;s Technical Assistance Center (TAC) about upgrade options.<\/p>\n<h3>If You Cannot Upgrade Yet<\/h3>\n<p>Until a fixed release is installed, Arista recommends these steps:<\/p>\n<ul>\n<li>Limit access to the VCO web interface to trusted administrative networks. This can reduce the risk of exposure.<\/li>\n<li>Monitor the VCO for access from known malicious IP addresses.<\/li>\n<li>Monitor for unexpected outbound network traffic from the VCO host.<\/li>\n<li>Consider blocking outbound ports that are not required for normal operation.<\/li>\n<li>Monitor for backdoor daemons and webshells.<\/li>\n<li>Review recent administrator activity for unexpected changes.<\/li>\n<\/ul>\n<h3>Signs of Compromise<\/h3>\n<p>Arista said no single indicator proves that a VCO was compromised through this flaw. Check VCO web access logs for requests with unusual URL-like paths, encoded characters, references to local or internal services, or high request rates.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The specific indicators to look for are:<\/p>\n<ul>\n<li><strong>File<\/strong>: <code>\/usr\/local\/sbin\/.vcnode.js<\/code><\/li>\n<li><strong>File<\/strong>: <code>\/usr\/local\/sbin\/vc-sysmond<\/code><\/li>\n<li><strong>MD5<\/strong> (<code>vc-sysmond<\/code>): <code>dc78e206eaeadec59fc5801fe4556bd0<\/code><\/li>\n<li><strong>File<\/strong>: <code>\/etc\/systemd\/system\/vc-sysmon.service<\/code><\/li>\n<li><strong>HTTP header<\/strong> in nginx logs: <code>x-vc-opt<\/code><\/li>\n<li><strong>IP<\/strong>: <code>142.93.149[.]77<\/code><\/li>\n<li><strong>IP<\/strong>: <code>104.248.126[.]159<\/code><\/li>\n<\/ul>\n<p>If you find any of these, preserve the state of the VCO and contact TAC or your Arista account team. If you suspect a compromise, save the VCO&#8217;s web access, backend application, system, and database logs and its file-system timestamps before you fix anything, where that is practical.<\/p>\n<p>Arista also advises incident response after upgrading. That may include rotating credentials, reviewing administrator activity, checking the state of managed Edge devices, and restoring or replacing the orchestrator from trusted sources.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Swati Khandelwal\ue802Sep 22, 2026Vulnerability \/ Network Security Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3058,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[201,3499,497,128,70,2754,1961,2753],"class_list":["post-3057","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-actively","tag-certificatebased","tag-cvss","tag-exploited","tag-flaw","tag-orchestrator","tag-setups","tag-velocloud"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3057","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3057"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3057\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3058"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3057"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3057"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3057"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}