CyberSecurity News
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
AI summary
A vulnerability in VeloCloud Orchestrator is being actively exploited by attackers. The flaw affects on-premises VeloCloud Orchestrator servers that manage Edge devices in a VeloCloud SD-WAN. It may allow a remote attacker without login access to access internal functions and impact the VCO host. The issue specifically impacts VeloCloud Orchestrator setups that use certificates to authenticate Edge devices. Arista disclosed the flaw on September 22. The vulnerability is tracked as CVE-2026-93952 and has a CVSS score of 10.0.
Vulnerabilities mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

