Executive Summary
Attackers are actively exploiting a critical CVSS 10.0 vulnerability (CVE-2026-93952) in Arista's VeloCloud Orchestrator that affects certificate-based SD-WAN deployments. The flaw allows remote attackers with no authentication to execute privileged functions and compromise the orchestrator host, potentially gaining access to all managed Edge devices and their data. Arista confirmed external discovery and active exploitation, with fixes available for some release trains but not others, leaving many enterprise SD-WAN infrastructures exposed.
This incident highlights the critical security risks in SD-WAN infrastructure as organizations increasingly rely on these solutions for hybrid connectivity, making orchestrator security paramount for preventing network-wide compromises.
Why This Matters Now
SD-WAN orchestrators are high-value targets controlling entire network infrastructures, and this maximum-severity flaw demonstrates how a single vulnerability can expose comprehensive enterprise connectivity, making immediate patching and monitoring essential.
Attack Path Analysis
Attackers exploited CVE-2026-93952, a CVSS 10.0 vulnerability in VeloCloud Orchestrator certificate-based authentication to gain unauthorized access to the management interface. Upon successful exploitation, attackers escalated privileges to internal VCO functions and deployed persistent backdoors including webshells and system daemons. The compromised orchestrator provided access to managed Edge devices across the SD-WAN infrastructure, enabling lateral movement throughout the network. Attackers established command and control channels through the VCO host while monitoring for detection. Data exfiltration likely occurred through the orchestrator's access to sensitive network configurations and managed device data. The attack resulted in full compromise of the SD-WAN management infrastructure with persistent access mechanisms.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-93952 in VeloCloud Orchestrator web interface, bypassing authentication in certificate-based Edge deployments to gain unauthorized access to internal VCO functions
Related CVEs
CVE-2026-93952
CVSS 10A remote code execution vulnerability in VeloCloud Orchestrator affects on-premises deployments using certificate-based authentication, allowing unauthenticated remote attackers to gain privileged access to internal functions.
Affected Products:
Arista VeloCloud Orchestrator – 5.2.3.15 and earlier, 6.1.3.7 and earlier, 6.4.2.7 and earlier, 7.0.0.2 and earlier
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Web Shell
Valid Accounts
Web Protocols
Data Destruction
Remote System Discovery
SMB/Windows Admin Shares
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Vulnerability Management Program
Control ID: 6.2.2
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.04(c)
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Network Segmentation
Control ID: ID.AM-1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2(a)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Critical exposure through SD-WAN infrastructure compromises enabling lateral movement, traffic interception, and control plane attacks affecting network operations and customer data.
Financial Services
VeloCloud orchestrator vulnerabilities threaten branch connectivity, transaction security, and regulatory compliance through potential network segmentation bypass and data exfiltration.
Health Care / Life Sciences
SD-WAN exploitation risks patient data exposure, HIPAA violations, and medical facility network integrity through compromised edge device management systems.
Government Administration
Certificate-based authentication flaws expose government networks to privilege escalation, sensitive data compromise, and critical infrastructure control system access.
Sources
- New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setupshttps://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.htmlVerified
- Arista Security Advisory 0183 - VeloCloud Orchestrator Remote Code Executionhttps://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183Verified
- Attackers Exploit Arista VeloCloud Orchestrator Vulnerabilityhttps://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have reduced the blast radius of this VeloCloud Orchestrator compromise by constraining lateral movement and limiting attacker reach across the SD-WAN infrastructure through network segmentation and controlled access paths.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud-native security fabric controls may have limited the scope of initial access by constraining network reachability to the VeloCloud Orchestrator management interface through distributed security enforcement points
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation policies may have constrained the attacker's ability to access privileged VCO functions by limiting lateral privilege expansion through workload-level access controls and identity-based authorization boundaries
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely have reduced the attacker's ability to move laterally from the compromised orchestrator to managed Edge devices by constraining inter-segment communications and enforcing microsegmentation policies
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility and control mechanisms may have constrained command and control communications by providing enhanced monitoring of traffic flows and potentially blocking suspicious outbound connections to attacker infrastructure
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely have limited data exfiltration by constraining outbound data flows from the compromised VCO environment and enforcing data loss prevention policies on sensitive network configuration data
The overall impact would likely have been reduced to localized compromise of the orchestrator with constrained ability to affect the broader SD-WAN infrastructure and connected network segments
Impact at a Glance
Affected Business Functions
- SD-WAN Network Management
- Remote Site Connectivity
- Network Traffic Orchestration
- Edge Device Management
Estimated downtime: 7 days
Estimated loss: N/A
Compromise of VeloCloud Orchestrator may expose network configuration data, authentication certificates, managed Edge device configurations, and potentially provide access to all connected network segments managed by the orchestrator
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate management interfaces from general network access and enforce least privilege access to critical infrastructure components
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic from management systems, blocking unauthorized C2 communications to suspicious IPs
- • Establish Multicloud Visibility & Control to detect anomalous interactions with management interfaces, including repeated malformed requests and suspicious automation patterns
- • Enable Threat Detection & Anomaly Response capabilities to baseline normal management traffic and alert on covert tools or unauthorized remote access attempts
- • Apply Inline IPS (Suricata) protection to inspect traffic to/from critical network management systems and block known exploit patterns targeting infrastructure vulnerabilities



