Home / Sep 24, 2026 / Story
0
#10 BleepingComputer general September 23, 2026 at 12:29 UTC

Arista patches actively exploited VeloCloud Orchestrator zero-day

By Sergiu Gatlan

AI Summary

Arista Networks released emergency patches for a zero-day vulnerability in VeloCloud Orchestrator (VCO) On-Prem deployments that is actively being exploited, allowing remote attackers to access privileged internal functionality without authentication. The flaw is rated critical severity, and Arista urged immediate patching for all on-premises VCO deployments. SD-WAN administrators running Arista VeloCloud should treat this as an urgent remediation priority.

Relevance score: 80.0/100

# More from September 24