Arista disclosed CVE-2026-93952 on September 22, 2026, a maximum-severity vulnerability under active exploitation that allows remote unauthenticated attackers to access privileged internal functions on on-premises VeloCloud Orchestrator servers.
The flaw affects the VeloCloud Orchestrator, the management server for Arista’s SD-WAN deployments. Only orchestrators configured to authenticate Edge devices using certificates are vulnerable. The vulnerability carries a CVSS score of 10.0, indicating complete compromise of confidentiality, integrity, and availability.
VeloCloud Orchestrator Manages SD-WAN Firewall and Routing Policy
VeloCloud Orchestrator functions as the central management and control plane for Arista’s SD-WAN deployments, formerly branded as VMware SD-WAN before Arista’s acquisition. The orchestrator manages Edge devices, configures routing policies, enforces firewall rules, and monitors network traffic across distributed branch locations.
Organizations deploy VeloCloud Orchestrator either as a cloud-hosted service or on-premises in their own data centers. CVE-2026-93952 affects only on-premises orchestrator deployments, not cloud-hosted instances managed by Arista.
CVE-2026-93952 Grants Unauthenticated Access to Privileged Internal Functions
CVE-2026-93952 allows a remote attacker with no authentication to access privileged internal functions on the VeloCloud Orchestrator. The disclosure does not specify which internal functions are exposed, but the CVSS 10.0 score indicates the attacker gains complete control over the orchestrator host.
Privileged access to the orchestrator translates to control over the entire SD-WAN fabric. An attacker compromising the orchestrator can modify routing policies, redirect traffic flows, extract encryption keys, disable firewall rules on managed Edge devices, or intercept traffic traversing the SD-WAN overlay network.
The unauthenticated nature of the vulnerability eliminates barriers to exploitation. No credentials, prior network access, or social engineering is required—only network connectivity to the orchestrator’s exposed interface.
Affects Only Certificate-Based Edge Authentication Configurations
The vulnerability exists only in VeloCloud Orchestrator deployments configured to authenticate Edge devices using certificates. Orchestrators using other authentication methods are not vulnerable to CVE-2026-93952.
Certificate-based authentication is a common deployment pattern for SD-WAN infrastructures where Edge devices authenticate to the orchestrator using X.509 certificates rather than shared secrets or password-based credentials. The flaw appears to reside in the certificate validation or processing logic, though Arista’s disclosure does not detail the specific code path exploited.
Organizations running VeloCloud Orchestrator must determine their Edge authentication configuration. If certificate-based authentication is enabled, the system is vulnerable and requires immediate patching.
Active Exploitation Confirmed by Arista
Arista confirmed active exploitation of CVE-2026-93952 in its September 22 disclosure. The vendor did not state when exploitation was first detected, how many organizations have been compromised, or whether the attacks are targeted or opportunistic.
Active exploitation of a CVSS 10.0 vulnerability in SD-WAN management infrastructure represents a critical threat. Attackers targeting VeloCloud Orchestrator can compromise the core control plane for an organization’s wide-area network, intercepting inter-site traffic, redirecting data flows, or disrupting connectivity across branch locations.
Arista Released Guidance and Patches September 22
Arista released disclosure and remediation guidance on September 22, 2026. Organizations running on-premises VeloCloud Orchestrator with certificate-based Edge authentication must apply patches immediately.
The disclosure did not specify the patch version number, provide a timeline for the fix’s development, or indicate whether Arista notified affected customers before public disclosure. The absence of advance warning means organizations learned of the active exploitation and maximum-severity rating simultaneously, compressing the time available for assessment and remediation.
Implications for SD-WAN Control Plane Security
CVE-2026-93952 demonstrates the catastrophic impact of unauthenticated remote code execution in SD-WAN management infrastructure. The orchestrator controls every Edge device, every routing decision, and every firewall rule across the deployment. A single vulnerability at this layer compromises the entire network fabric.
The maximum CVSS score of 10.0 reflects the complete absence of mitigating factors. The vulnerability requires no authentication, no user interaction, and no complex configuration—just network access to the orchestrator. Organizations that expose orchestrator management interfaces to the internet or to untrusted network segments face immediate risk.
Organizations using VeloCloud Orchestrator in certificate-based authentication mode should apply patches immediately, audit orchestrator access logs for unauthorized activity, review Edge device configurations for unexpected policy changes, and inspect network traffic flows for anomalies that could indicate attacker-controlled routing modifications.
The combination of active exploitation, maximum severity, and unauthenticated access makes CVE-2026-93952 one of the most critical SD-WAN vulnerabilities disclosed in recent years. Organizations cannot defer patching without accepting the risk of complete SD-WAN infrastructure compromise.
