The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In September 2026, Arista Networks disclosed CVE-2026-93952, a maximum-severity zero-day vulnerability in VeloCloud Orchestrator (VCO) On-Prem deployments that was being actively exploited. The flaw stems from improper input validation in certificate-based authentication, allowing remote attackers to access privileged internal VCO host functionality without requiring system privileges or user interaction. The U.S. CISA immediately added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated federal agencies secure their networks within 48 hours.

This incident highlights the escalating threat to SD-WAN infrastructure as organizations increasingly rely on hybrid connectivity solutions. With Arista being a Fortune 500 company serving over 10,000 customers worldwide, this zero-day demonstrates how critical network infrastructure remains a high-value target for sophisticated threat actors seeking to compromise enterprise connectivity and potentially pivot to broader network access.

Why This Matters Now

SD-WAN platforms are becoming primary attack vectors as they sit at the intersection of cloud and on-premises networks, providing attackers with potential access to entire enterprise infrastructures through a single compromise point.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The vulnerability allows remote attackers to access privileged VCO functionality without requiring authentication or user interaction, and it affects certificate-based authentication mechanisms critical to SD-WAN security.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain attacker movement and reduce blast radius through segmented access controls and east-west traffic enforcement. The multi-stage SD-WAN compromise demonstrates how segmentation boundaries could limit lateral expansion across connected enterprise locations.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Zero Trust segmentation boundaries would likely limit the scope of initial access by constraining which internal VCO host functions could be reached from compromised entry points.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Micro-segmentation policies would likely constrain privilege escalation by limiting which administrative functions and system resources could be accessed from compromised host contexts.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic enforcement would likely constrain lateral movement by blocking unauthorized communication paths between the compromised VCO and connected edge devices across network segments.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Network visibility and traffic analysis capabilities would likely detect and constrain suspicious communication patterns by identifying anomalous outbound connections and encoded traffic flows.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely constrain data exfiltration by limiting which outbound communication paths and destinations could be accessed from compromised VCO systems.

Impact (Mitigations)

While operational disruption may still occur at compromised locations, segmentation boundaries would likely reduce the blast radius by limiting attacker reach to isolated network segments rather than entire enterprise infrastructure.

Impact at a Glance

Affected Business Functions

  • Network Infrastructure Management
  • SD-WAN Operations
  • Remote Site Connectivity
  • Network Security Administration
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of network configuration data, VeloCloud orchestrator administrative functions, and internal network topology information through privileged VCO host access

Recommended Actions

  • • Implement Zero Trust Segmentation to isolate SD-WAN management infrastructure from production networks, preventing lateral movement from compromised orchestrators to connected edge devices
  • • Deploy Egress Security & Policy Enforcement to detect and block suspicious outbound communications from management systems, including unexpected HTTP/HTTPS traffic patterns and connections to malicious IP addresses
  • • Enable Multicloud Visibility & Control to monitor for anomalous interactions with centralized management platforms, detecting unusual request patterns, high request rates, and suspicious HTTP headers like x-vc-opt
  • • Implement Inline IPS (Suricata) to identify and block exploit attempts targeting known CVEs in network management systems, providing signature-based detection for malicious payloads and attack patterns
  • • Deploy Cloud Native Security Fabric (CNSF) for real-time inspection and autonomous response to zero-day exploits, enabling distributed policy enforcement that can detect and mitigate novel attack patterns targeting critical infrastructure components

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image