Arista Networks security advisory (AV26-947)

CriticalCVSS 10.0Canadian Centre for Cyber Security · Canadian Centre for Cyber Security·

At a glance

Severity
CriticalCVSS 10.0
Used in attacks
Yes, 1 of 1 flaw named
Flaws named
CVE-2026-93952
Reported by
1 outlet

As of September 22, 2026, Arista Networks is affected by a vulnerability in the following product:

  • VeloCloud Orchestrator (VCO) On-Prem
    • Versions 5.2.0 to 5.2.3.15
    • Versions 6.1.0 to 6.1.3.7
    • Versions 6.4.0 to 6.4.2.7
    • Versions 7.0.0 to 7.0.0.2

Open-source reporting indicates that CVE-2026-93952 is being exploited in the wild.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Originally published by Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.

Vulnerabilities referenced

  • CVE-2026-9395210.0Critical

    Arista VeloCloud Orchestrator

    Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

    Used in attacks

    Added to CISA's list 2026-09-22 · Patch or advisory available

    Full record →

Fastnexa security experts

This story involves a flaw attackers are already using. Are you exposed?

A Fastnexa penetration tester can check whether CVE-2026-93952 or anything like it can be used against your websites, apps and network.

Book a 30-min callWhatsApp us

Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →

Coverage

One outlet has carried this so far.

  1. Canadian Centre for Cyber Security ↗Official SourceFirst reported

    2026-09-22 13:14 UTC

Related stories