# Arista Networks Issues Critical Patch for VeloCloud Zero-Day Vulnerability

*Published September 25, 2026*
*Source: [https://www.news4hackers.com/arista-fixes-critical-zero-day-in-velocloud-orchestrator/](https://www.news4hackers.com/arista-fixes-critical-zero-day-in-velocloud-orchestrator/)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/arista-networks-issues-critical-patch-for-velocloud-zero-day-vulnerability) or [see plans](https://www.sec-news.ai/pricing).*

## Article

Arista Networks has released crucial security updates to fix a zero-day vulnerability in its VeloCloud Orchestrator on-premises deployments. This flaw, identified as CVE-2026-93952, is caused by insufficient input validation and affects systems using certificate-based authentication between VeloCloud Edge devices and the VCO platform. Attackers can exploit this vulnerability to access privileged internal functions with minimal effort and without needing system-level privileges or user interaction. Arista has already rolled out patches for hosted VCO instances running versions 5.2.3.16 and later, and 6.4.2.8 and later, while patches for older versions are also in progress. The U.S. Cybersecurity and Infrastructure Security Agency has recognized the severity of CVE-2026-93952 by adding it to its Known Exploited Vulnerabilities catalog. Federal civilian executive branch agencies have been instructed to implement necessary protective measures by September 25. Security teams are advised to limit access to the VCO web interface, audit administrator activity, and monitor for suspicious connections. Indicators of compromise include encoded requests, unusual URLs, and high-volume traffic. Specific IP addresses have been identified for blocking, and unusual outbound traffic from the VCO host should be investigated. This is the third zero-day vulnerability that Arista has addressed this year, following previous patches for CVE-2026-7473 and CVE-2026-16812, both of which were actively exploited. Arista Networks, serving over 10,000 global customers, continues to respond proactively to security threats, and customers are urged to contact their Technical Assistance Center for further support.
