CVE-2026-93952 should be handled as a potential compromise of the management plane. Arista rates the VeloCloud Orchestrator issue at CVSS 10.0 and says it has been actively exploited. The vulnerable target is the on-premises VCO web interface; the attack does not require tenant or operator credentials. Hosted and dedicated environments have already been patched by the provider, but organizations operating their own orchestrator must act directly.
The priority is to contain access, preserve evidence, upgrade to a fixed release, and decide whether the orchestrator can still be trusted. Because VCO coordinates SD-WAN infrastructure, a compromised instance may expose configuration, inventory, credentials, certificates, and operational data.
Identify affected orchestrators
According to Arista Security Advisory 0183, affected on-premises releases include 5.2.3.15 and earlier in the 5.2 branch, 6.1.3.7 and earlier in 6.1, 6.4.2.7 and earlier in 6.4, and 7.0.0.2 and earlier in 7.0. Inventory production, standby, lab, and recovery appliances; forgotten management systems are often the easiest targets.
Map every route to the VCO web interface. Include public addresses, VPN access, partner networks, bastion hosts, and load balancers. The exploit requires network access to the web service and certificate-based Edge-to-VCO authentication, so reachability is a critical control.
Contain before upgrading
Restrict the web interface to trusted administration networks immediately. Use an upstream firewall or reverse proxy so the control remains effective even if the appliance configuration is already suspect. Do not expose the interface merely because authentication is enabled.
Before rebooting or changing the system, preserve web, backend, database, and operating-system logs. Export diagnostic bundles and record file timestamps, running processes, listening sockets, scheduled jobs, and outbound connections. If the environment is high impact, capture a disk snapshot or equivalent forensic image under your incident-response procedure.
Search for published indicators and suspicious behavior
Arista lists several indicators that warrant immediate escalation: files named /usr/local/sbin/.vcnode.js or /usr/local/sbin/vc-sysmond, the service file /etc/systemd/system/vc-sysmon.service, the HTTP header x-vc-opt, the MD5 value dc78e206eaeadec59fc5801fe4556bd0, and communications with 142.93.149.77 or 104.248.126.159. Their absence does not establish safety; attackers can change infrastructure and tooling.
Also review unexpected command execution, file creation, configuration changes, database exports, maintenance actions, and outbound HTTP or HTTPS sessions. Correlate VCO activity with firewall, DNS, proxy, and identity logs. Check for unplanned Edge software updates or version changes, because management-plane access can be used to alter downstream devices.
Upgrade or rebuild
Move to the fixed release for the supported train. If no fixed build is available for the deployed branch, contact Arista TAC rather than improvising a downgrade or unsupported package. After the upgrade, confirm the reported version from the appliance itself and verify that all cluster members are consistent.
If indicators, unexplained privileged activity, or data access are found, do not treat patching as eradication. Build a clean orchestrator, restore only reviewed configuration, replace certificates and keys, rotate credentials stored or used by VCO, and re-enroll components where appropriate. Scope the incident to systems that trusted the orchestrator.
Assess downstream impact
VCO compromise can affect more than the orchestrator host. Review administrative and automated changes pushed to Edges during the exposure window. Compare intended templates with the effective device configuration, paying attention to DNS, routing, tunnels, authentication, software images, and remote-access settings. Validate that no unexpected administrator, API credential, or integration endpoint was introduced.
Coordinate with network operations before broad credential or certificate rotation. Replacing trust material without a staged plan can disconnect remote sites and destroy useful evidence. Build an order of operations: preserve artifacts, establish a clean management path, rotate the highest-risk secrets, verify connectivity, and then retire the old trust anchors.
If a dedicated or hosted environment is in use, obtain provider confirmation of the patch state and exposure window. Provider-managed patching reduces the customer’s upgrade work but does not replace review of tenant audit logs or unexpected configuration changes.
Close with evidence
A defensible closure record should contain the inventory, exposure map, preserved logs, indicator search, version evidence, network restriction, and the decision to upgrade in place or rebuild. CISA added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog, so organizations should be able to demonstrate both remediation and compromise assessment.

