Column 1
Skip to content

VeloCloud Orchestrator CVE-2026-93952: Patch and Exposure Checklist

September 23, 2026

Update September 23, 2026: CISA lists CVE-2026-93952 in its Known Exploited Vulnerabilities catalog, and Arista says the VeloCloud Orchestrator issue is being actively exploited. Operators of on-premises VeloCloud Orchestrator should identify their release train, restrict management access, and move to a fixed release as soon as their supported path allows. Do not assume that every VeloCloud Edge or Gateway is affected: Arista identifies the Orchestrator as the affected product.

Which releases need attention?

Arista lists VeloCloud Orchestrator on-prem releases through 5.2.3.15 in the 5.2.x train, 6.1.3.7 in the 6.1.x train, 6.4.2.7 in the 6.4.x train, and 7.0.0.2 in the 7.0.x train as affected. Its advisory lists 5.2.3.16 or later in the 5.2.3 train and 6.4.2.8 or later in the 6.4.2 train as fixed at this writing. Other supported trains may receive fixes later; operators should check the live vendor advisory and contact Arista TAC for a supported upgrade path rather than treating a different train’s version number as a universal fix.

Arista says its hosted, including Dedicated, Orchestrator deployments were impacted and have already been patched. The vendor describes a configuration-dependent exposure involving certificate-based Edge-to-Orchestrator authentication and network access to the Orchestrator’s web interface. Confirm your own configuration and installed version with the product owner before declaring an instance unaffected.

What administrators should do

  1. Inventory each on-premises Orchestrator, its release train, owner, and management exposure. Check the exact build against Arista’s current affected and fixed version tables.
  2. Restrict Orchestrator web-interface access to trusted administrative networks while arranging the supported update. Preserve legitimate Edge management and monitoring when applying temporary network controls.
  3. Plan the vendor-supported upgrade with the network team. Confirm compatibility, maintenance timing, recovery options, and post-upgrade access before changing a production orchestrator.
  4. If compromise is suspected, preserve relevant access, application, and system evidence under the incident-response process before remediation. Review unexpected administrative changes, outbound activity, and managed-device state without publishing sensitive logs or customer information.
  5. After the update, confirm the installed build, administrator access, Edge connectivity, managed policy state, and monitoring. Follow the vendor’s incident-response guidance for credential and orchestrator recovery if compromise is confirmed.

For other confirmed patch priorities, see the Fix I.T. Phill security updates archive.

Sources: Arista security advisory 0183 and the CISA Known Exploited Vulnerabilities catalog. This is protective guidance based on those sources; Fix I.T. Phill has not independently verified exploitation in a customer environment.