Arista Networks pushed an emergency patch this month for a maximum-severity vulnerability in its VeloCloud Orchestrator software that the company says is already being actively exploited by remote attackers, prompting the U.S. Cybersecurity and Infrastructure Security Agency to order federal agencies to patch it by September 25.

The flaw, tracked as CVE-2026-93952, affects on-premises deployments of VeloCloud Orchestrator, the management platform administrators use to configure and monitor Arista's SD-WAN edge devices across an organization's network. Arista rated the vulnerability at the maximum possible severity on the industry-standard scale and confirmed it was identified through external reporting rather than the company's own internal testing, meaning someone outside Arista found and reported active exploitation before the company had a fix ready.

Why it's rated as severe as a vulnerability gets

The vulnerability stems from improper input validation in how VeloCloud Orchestrator handles authentication for VeloCloud Edge devices connecting to it through certificate-based authentication. Critically, Arista confirmed that exploiting the flaw requires only network access to the orchestrator's web interface and the public portion of a VeloCloud Edge device's authentication certificate, information that is not treated as secret in normal operation. No valid administrator credentials are needed at all.

That combination, a maximum severity rating, active exploitation already underway, and a path to compromise that bypasses authentication entirely rather than merely weakening it, is what pushed CISA to issue an emergency binding directive rather than treating this as a routine patch-when-convenient advisory.

How attackers are using it

Security researchers tracking exploitation in the wild have published indicators including two specific IP addresses, 142.93.149.77 and 104.248.126.159, associated with active attack traffic, along with guidance for defenders on what to look for: unusual administrator activity in orchestrator logs, suspicious requests in web access logs containing encoded characters, and abnormally high request rates against the orchestrator's web interface, all signs consistent with automated exploitation attempts probing for vulnerable, unpatched systems.

Because VeloCloud Orchestrator sits at the center of an organization's SD-WAN management, a successful compromise doesn't just expose the orchestrator itself. An attacker with control over the platform that manages an organization's wide-area network edge devices is positioned to manipulate network configuration, intercept or redirect traffic, and pivot toward other systems the SD-WAN infrastructure touches, which is typically most of an organization's branch office and remote-site connectivity.

What organizations need to do now

Arista and independent researchers have converged on a consistent set of urgent recommendations: apply the available patch immediately rather than waiting for a scheduled maintenance window, restrict access to the VeloCloud Orchestrator web interface to administrative networks only rather than leaving it reachable from the broader internet or internal network, and review both administrator activity logs and web access logs for any of the indicators of suspicious activity researchers have published.

Organizations that suspect they may already be compromised are advised to preserve logs before applying remediation steps, since patching alone will close the vulnerability going forward but will not retroactively remove access an attacker may have already established through it. CISA's binding directive applies formally only to federal civilian agencies, but security researchers are urging private-sector organizations running VeloCloud Orchestrator on-premises to treat the September 25 deadline as their own, given the flaw is confirmed under active exploitation rather than merely theoretical.

Sources