Home / Sep 23, 2026 / Story
0
#7 The Hacker News general September 22, 2026 at 12:29 UTC

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

By [email protected] (The Hacker News)

AI Summary

CVE-2026-93952 (CVSS 10.0) is a critical flaw in on-premises Arista VeloCloud Orchestrator actively exploited in the wild, enabling unauthenticated remote attackers to access privileged internal functions and affect the VCO host. Only orchestrators using certificate-based Edge authentication are vulnerable. SD-WAN operators running on-prem VCO deployments should treat this as a priority patch given active exploitation and maximum CVSS score.

Relevance score: 84.0/100

# More from September 23