DEV Community

Cover image for Arista Networks Patches Critical VeloCloud Orchestrator Zero-Day Exploited in the Wild
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Arista Networks Patches Critical VeloCloud Orchestrator Zero-Day Exploited in the Wild

Summary

Arista Networks disclosed a critical CVSS 10.0 vulnerability (CVE-2026-93952) in VeloCloud Orchestrator On-Prem that is being actively exploited to gain unauthenticated remote access to orchestrator hosts and managed edge devices.

Take Action:

If you run VeloCloud Orchestrator On-Prem, this is urgent. Make sure its web interface is not reachable from the internet and is accessible only from trusted admin networks, then update right away to a fixed version (5.2.3.16, 6.4.2.8 or later). Attackers are already using this flaw to take full control without any password. After patching, look for the hidden file /usr/local/sbin/.vcnode.js or the x-vc-opt header in your web logs, and if you find either, treat the orchestrator and every connected Edge device as compromised.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)