The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

Attackers are actively exploiting a critical CVSS 10.0 vulnerability (CVE-2026-93952) in Arista's VeloCloud Orchestrator that affects certificate-based SD-WAN deployments. The flaw allows remote attackers with no authentication to execute privileged functions and compromise the orchestrator host, potentially gaining access to all managed Edge devices and their data. Arista confirmed external discovery and active exploitation, with fixes available for some release trains but not others, leaving many enterprise SD-WAN infrastructures exposed.

This incident highlights the critical security risks in SD-WAN infrastructure as organizations increasingly rely on these solutions for hybrid connectivity, making orchestrator security paramount for preventing network-wide compromises.

Why This Matters Now

SD-WAN orchestrators are high-value targets controlling entire network infrastructures, and this maximum-severity flaw demonstrates how a single vulnerability can expose comprehensive enterprise connectivity, making immediate patching and monitoring essential.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Only on-premises VeloCloud Orchestrators configured with certificate-based authentication from Edge devices are vulnerable. Deployments using pre-shared key authentication are not affected.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely have reduced the blast radius of this VeloCloud Orchestrator compromise by constraining lateral movement and limiting attacker reach across the SD-WAN infrastructure through network segmentation and controlled access paths.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud-native security fabric controls may have limited the scope of initial access by constraining network reachability to the VeloCloud Orchestrator management interface through distributed security enforcement points

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation policies may have constrained the attacker's ability to access privileged VCO functions by limiting lateral privilege expansion through workload-level access controls and identity-based authorization boundaries

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic enforcement would likely have reduced the attacker's ability to move laterally from the compromised orchestrator to managed Edge devices by constraining inter-segment communications and enforcing microsegmentation policies

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility and control mechanisms may have constrained command and control communications by providing enhanced monitoring of traffic flows and potentially blocking suspicious outbound connections to attacker infrastructure

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security controls would likely have limited data exfiltration by constraining outbound data flows from the compromised VCO environment and enforcing data loss prevention policies on sensitive network configuration data

Impact (Mitigations)

The overall impact would likely have been reduced to localized compromise of the orchestrator with constrained ability to affect the broader SD-WAN infrastructure and connected network segments

Impact at a Glance

Affected Business Functions

  • SD-WAN Network Management
  • Remote Site Connectivity
  • Network Traffic Orchestration
  • Edge Device Management
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: N/A

Data Exposure

Compromise of VeloCloud Orchestrator may expose network configuration data, authentication certificates, managed Edge device configurations, and potentially provide access to all connected network segments managed by the orchestrator

Recommended Actions

  • Implement Zero Trust Segmentation to isolate management interfaces from general network access and enforce least privilege access to critical infrastructure components
  • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic from management systems, blocking unauthorized C2 communications to suspicious IPs
  • Establish Multicloud Visibility & Control to detect anomalous interactions with management interfaces, including repeated malformed requests and suspicious automation patterns
  • Enable Threat Detection & Anomaly Response capabilities to baseline normal management traffic and alert on covert tools or unauthorized remote access attempts
  • Apply Inline IPS (Suricata) protection to inspect traffic to/from critical network management systems and block known exploit patterns targeting infrastructure vulnerabilities

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image