Site icon Windows Mode

On-Prem VeloCloud Orchestrator Under Attack: Patch Guide

Velocloud orchestrator - On-Prem VeloCloud Orchestrator Under Attack: Patch Guide

Velocloud orchestrator from On-Prem VeloCloud Orchestrator Under Attack: Patch Guide

Critical Alert
CVE-2026-93952 • CVSS 10.0

Attackers are actively targeting on-premises VMware VeloCloud Orchestrator (VCO) servers. While hosted cloud setups are already secured, on-prem environments require immediate action because only selected software versions have received security patches so far.

What Happened

Arista has issued an urgent warning regarding a critical vulnerability affecting on-premises VeloCloud Orchestrator systems. Security research firm Qualys identifies the flaw as an improper input validation and cross-site request forgery (CSRF) exploit. If triggered, remote attackers can bypass regular authentication to reach privileged administrative functions and take control of the host machine.

According to details tracked in NetworkWorld’s security advisory coverage, Hosted and Dedicated cloud VCO instances were updated automatically by the vendor. However, self-hosted on-premises deployments remain vulnerable until administrators apply the latest patches or network restrictions.

Version Breakdown and Patch Availability

Not every software train has an available update right now. Use the breakdown below to check whether your release can be upgraded immediately or requires interim firewall safeguards.

Release Train Vulnerable Versions Patched Release Status
5.2.x 5.2.3.15 and earlier 5.2.3.16 or higher Patch Ready
6.1.x 6.1.3.7 and earlier None yet Pending Fix
6.4.x 6.4.2.7 and earlier 6.4.2.8 or higher Patch Ready
7.0.x 7.0.0.2 and earlier None yet Pending Fix

How the Vulnerability Operates

An attacker does not need an existing operator account, admin login, or tenant credentials to initiate the attack. However, a successful exploit relies on specific conditions being true in your setup:

1. Public Interface Exposure
The VCO web interface is directly reachable over the local network or the public internet.
2. Active Edge Certificate Pairing
Certificate-based authentication is enabled between your managed VeloCloud Edge hardware and the Orchestrator.
3. Public Key Discovery
The attacker acquires the public key associated with the Edge authentication certificate.

Steps to Protect Your Network

Because this vulnerability is being actively exploited in the wild, network teams should implement defenses immediately without waiting for full release cycles:

  1. Upgrade supported versions: If you run the 5.2.x or 6.4.x trains, install version 5.2.3.16 or 6.4.2.8 right away.
  2. Restrict administrative access: For systems on trains 6.1.x and 7.0.x where patches are still in development, block internet access to the VCO web UI. Place the portal behind a private management subnet or trusted admin VPN.
  3. Review access logs: Check inbound web traffic and authentication logs for unexpected CSRF activity or unfamiliar connection handshakes originating from outside your standard network segments.
Exit mobile version