SPOJENO AI KEV ✓ EPSS 0.01
Arista patches actively exploited VeloCloud Orchestrator zero-day
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. [...]
Arista Networks Arista VeloCloud US FI NL CA
CVE v události 1
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-93952 | 10.0 3.1 · Arista 9.5 4.0 · Arista | KEV ✓ | 0.01 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 10.0.
Tahle CVE jsem vytáhl z širšího textu článku: CVE-2026-16812, CVE-2026-7473. Neukazuju u nich proto fakta z katalogů výše, a to preventivně, protože článek se na ně mohl jen odkazovat, třeba jako na starší kauzu.
Jak se o tom psalo 5
-
· BleepingComputer US nadpis události
Arista patches actively exploited VeloCloud Orchestrator zero-day
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. [...]
-
· NCSC-FI FI
Arista VeloCloud Orchestrator - Actively Exploited Critical Vulnerability
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 10.0, CVEs: CVE-2026-93952, Summary: Arista has disclosed a critical vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments that can allow a remote attacker to access privileged internal functionality and compromise the VCO host and data managed by the orchestrator. The vulnerability is actively exploited. Exploitation requires certificate-based authentication between VeloCloud Edge and VCO to be…
-
· NCSC-NL NL
NCSC-2026-0385 [1.00] [M/H] Kwetsbaarheid verholpen in VeloCloud Orchestrator (VCO) on-premises
VeloCloud heeft een kwetsbaarheid verholpen in VeloCloud Orchestrator (VCO) on-premises. De kwetsbaarheid in VCO stelt externe aanvallers in staat om toegang te krijgen tot geprivilegieerde interne functionaliteit, wat de vertrouwelijkheid, integriteit en beschikbaarheid kan aantasten. De kwetsbaarheid wordt actief uitgebuit en is in hosted VCO-omgevingen reeds verholpen. Beperk de toegang tot de VCO-webinterface tot vertrouwde administratieve netwerken om de blootstelling aan de kwetsbaarheid…
-
· Cyber Centre Kanada CA
Arista Networks security advisory (AV26-947)
Serial number: AV26-947Date: September 22, 2026 As of September 22, 2026, Arista Networks is affected by a vulnerability in the following product: VeloCloud Orchestrator (VCO) On-Prem Versions 5.2.0 to 5.2.3.15 Versions 6.1.0 to 6.1.3.7 Versions 6.4.0 to 6.4.2.7 Versions 7.0.0 to 7.0.0.2 Open-source reporting indicates that CVE-2026-93952 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they…
-
· CISA KEV US
Arista VeloCloud Orchestrator Improper Input Validation Vulnerability (CVE-2026-93952)
CISA added CVE-2026-93952 to the Known Exploited Vulnerabilities catalog. Affected product: Arista VeloCloud Orchestrator. Remediation due date: 2026-09-25.