Arista said on September 22 that attackers are actively exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages Edge devices in a VeloCloud SD-WAN deployment. The vulnerability, tracked as CVE-2026-93952, has been assigned a CVSS score of 10.0, the maximum possible severity.

The flaw may allow a remote attacker with no login access to escalate privileges, according to the advisory. Arista specifically noted that the vulnerability is being exploited in certificate-based setups, making this a pressing concern for organizations relying on VCO as a central management point for their SD-WAN infrastructure.

Because VCO holds a privileged position in the network, successful exploitation could give an attacker significant control over managed Edge devices. Organizations running affected on-premises VCO instances should watch for updated guidance from Arista and take steps to secure their deployments against ongoing attacks.