Executive Summary
In September 2026, Arista Networks disclosed CVE-2026-93952, a maximum-severity zero-day vulnerability in VeloCloud Orchestrator (VCO) On-Prem deployments that was being actively exploited. The flaw stems from improper input validation in certificate-based authentication, allowing remote attackers to access privileged internal VCO host functionality without requiring system privileges or user interaction. The U.S. CISA immediately added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated federal agencies secure their networks within 48 hours.
This incident highlights the escalating threat to SD-WAN infrastructure as organizations increasingly rely on hybrid connectivity solutions. With Arista being a Fortune 500 company serving over 10,000 customers worldwide, this zero-day demonstrates how critical network infrastructure remains a high-value target for sophisticated threat actors seeking to compromise enterprise connectivity and potentially pivot to broader network access.
Why This Matters Now
SD-WAN platforms are becoming primary attack vectors as they sit at the intersection of cloud and on-premises networks, providing attackers with potential access to entire enterprise infrastructures through a single compromise point.
Attack Path Analysis
Attackers exploited CVE-2026-93952, an improper input validation vulnerability in Arista VeloCloud Orchestrator, using certificate-based authentication bypass to gain privileged access to internal VCO host functionality. With initial access established, threat actors likely escalated privileges within the VCO system, moved laterally across connected SD-WAN infrastructure, maintained persistence through C2 communications from suspicious IP addresses, exfiltrated sensitive network configuration data, and potentially disrupted SD-WAN operations affecting connected enterprise locations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Remote attackers exploited CVE-2026-93952 improper input validation vulnerability in VeloCloud Orchestrator web interface, using public portion of VeloCloud Edge authentication certificates to bypass authentication and access privileged internal VCO host functionality without requiring valid credentials or user interaction
Related CVEs
CVE-2026-93952
CVSS 10An improper input validation vulnerability in Arista VeloCloud Orchestrator (VCO) On-Prem deployments allows remote attackers to access privileged internal VCO host functionality without authentication when certificate-based authentication is configured.
Affected Products:
Arista Networks VeloCloud Orchestrator (VCO) – 5.2.3.15 and below, 6.1.3.7 and below, 6.4.2.7 and below, 7.0.0.2 and below
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Valid Accounts: Local Accounts
Use Alternate Authentication Material: Application Access Token
Acquire Infrastructure: Virtual Private Server
Application Layer Protocol: Web Protocols
Data from Local System
Data Manipulation: Stored Data Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Vulnerability Management Program
Control ID: 11.3.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA Zero Trust Maturity Model 2.0 – Network Access Control
Control ID: Networks.L3.Nm.A.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2(a)
NIST Cybersecurity Framework 2.0 – Threat and Vulnerability Information is Received
Control ID: ID.RA-07
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
VeloCloud SD-WAN zero-day exploitation poses critical risk to network infrastructure, enabling privileged access to centralized management platforms controlling nationwide communications systems.
Financial Services
Maximum-severity CVE-2026-93952 threatens SD-WAN deployments managing secure financial networks, potentially compromising encrypted traffic and violating PCI DSS compliance requirements.
Health Care / Life Sciences
Actively exploited VeloCloud Orchestrator vulnerability endangers healthcare SD-WAN infrastructure, risking HIPAA violations through unauthorized access to encrypted patient data channels.
Government Administration
CISA's federal remediation mandate highlights critical government exposure to SD-WAN zero-day attacks targeting certificate-based authentication and centralized network management systems.
Sources
- Arista patches actively exploited VeloCloud Orchestrator zero-dayhttps://www.bleepingcomputer.com/news/security/arista-patches-actively-exploited-velocloud-orchestrator-zero-day/Verified
- Security Advisory 0183 - VeloCloud Orchestrator Authentication Bypass Vulnerabilityhttps://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183Verified
- CISA Adds Four Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalogVerified
- CVE-2026-93952 Detail - NVDhttps://nvd.nist.gov/vuln/detail/cve-2026-93952Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain attacker movement and reduce blast radius through segmented access controls and east-west traffic enforcement. The multi-stage SD-WAN compromise demonstrates how segmentation boundaries could limit lateral expansion across connected enterprise locations.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust segmentation boundaries would likely limit the scope of initial access by constraining which internal VCO host functions could be reached from compromised entry points.
Control: Zero Trust Segmentation
Mitigation: Micro-segmentation policies would likely constrain privilege escalation by limiting which administrative functions and system resources could be accessed from compromised host contexts.
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely constrain lateral movement by blocking unauthorized communication paths between the compromised VCO and connected edge devices across network segments.
Control: Multicloud Visibility & Control
Mitigation: Network visibility and traffic analysis capabilities would likely detect and constrain suspicious communication patterns by identifying anomalous outbound connections and encoded traffic flows.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely constrain data exfiltration by limiting which outbound communication paths and destinations could be accessed from compromised VCO systems.
While operational disruption may still occur at compromised locations, segmentation boundaries would likely reduce the blast radius by limiting attacker reach to isolated network segments rather than entire enterprise infrastructure.
Impact at a Glance
Affected Business Functions
- Network Infrastructure Management
- SD-WAN Operations
- Remote Site Connectivity
- Network Security Administration
Estimated downtime: 3 days
Estimated loss: N/A
Potential exposure of network configuration data, VeloCloud orchestrator administrative functions, and internal network topology information through privileged VCO host access
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate SD-WAN management infrastructure from production networks, preventing lateral movement from compromised orchestrators to connected edge devices
- • Deploy Egress Security & Policy Enforcement to detect and block suspicious outbound communications from management systems, including unexpected HTTP/HTTPS traffic patterns and connections to malicious IP addresses
- • Enable Multicloud Visibility & Control to monitor for anomalous interactions with centralized management platforms, detecting unusual request patterns, high request rates, and suspicious HTTP headers like x-vc-opt
- • Implement Inline IPS (Suricata) to identify and block exploit attempts targeting known CVEs in network management systems, providing signature-based detection for malicious payloads and attack patterns
- • Deploy Cloud Native Security Fabric (CNSF) for real-time inspection and autonomous response to zero-day exploits, enabling distributed policy enforcement that can detect and mitigate novel attack patterns targeting critical infrastructure components



