CVE-2026-93952 • CVSS 10.0
Attackers are actively targeting on-premises VMware VeloCloud Orchestrator (VCO) servers. While hosted cloud setups are already secured, on-prem environments require immediate action because only selected software versions have received security patches so far.
What Happened
Arista has issued an urgent warning regarding a critical vulnerability affecting on-premises VeloCloud Orchestrator systems. Security research firm Qualys identifies the flaw as an improper input validation and cross-site request forgery (CSRF) exploit. If triggered, remote attackers can bypass regular authentication to reach privileged administrative functions and take control of the host machine.
According to details tracked in NetworkWorld’s security advisory coverage, Hosted and Dedicated cloud VCO instances were updated automatically by the vendor. However, self-hosted on-premises deployments remain vulnerable until administrators apply the latest patches or network restrictions.
Version Breakdown and Patch Availability
Not every software train has an available update right now. Use the breakdown below to check whether your release can be upgraded immediately or requires interim firewall safeguards.
| Release Train | Vulnerable Versions | Patched Release | Status |
|---|---|---|---|
| 5.2.x | 5.2.3.15 and earlier | 5.2.3.16 or higher | Patch Ready |
| 6.1.x | 6.1.3.7 and earlier | None yet | Pending Fix |
| 6.4.x | 6.4.2.7 and earlier | 6.4.2.8 or higher | Patch Ready |
| 7.0.x | 7.0.0.2 and earlier | None yet | Pending Fix |
How the Vulnerability Operates
An attacker does not need an existing operator account, admin login, or tenant credentials to initiate the attack. However, a successful exploit relies on specific conditions being true in your setup:
The VCO web interface is directly reachable over the local network or the public internet.
Certificate-based authentication is enabled between your managed VeloCloud Edge hardware and the Orchestrator.
The attacker acquires the public key associated with the Edge authentication certificate.
Steps to Protect Your Network
Because this vulnerability is being actively exploited in the wild, network teams should implement defenses immediately without waiting for full release cycles:
- Upgrade supported versions: If you run the 5.2.x or 6.4.x trains, install version 5.2.3.16 or 6.4.2.8 right away.
- Restrict administrative access: For systems on trains 6.1.x and 7.0.x where patches are still in development, block internet access to the VCO web UI. Place the portal behind a private management subnet or trusted admin VPN.
- Review access logs: Check inbound web traffic and authentication logs for unexpected CSRF activity or unfamiliar connection handshakes originating from outside your standard network segments.
