Apply the latest security patches released by Arista and VMware for VeloCloud Orchestrator immediately. If patching is not immediately possible, consider disabling certificate-based Edge authentication, noting this will impact Edge connectivity. Monitor Arista and VMware security advisories for further guidance.
Quick answers
What is CVE-2026-93952?
Apply the latest security patches released by Arista and VMware for VeloCloud Orchestrator immediately. If patching is not immediately possible, consider disabling certificate-based Edge authentication, noting this will impact Edge connectivity. Monitor Arista and VMware security advisories for further guidance.
How severe is CVE-2026-93952?
critical, CVSS 10
Is CVE-2026-93952 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-93952 be mitigated?
Apply the latest security patches released by Arista and VMware for VeloCloud Orchestrator immediately. If patching is not immediately possible, consider disabling certificate-based Edge authentication, noting this will impact Edge connectivity. Monitor Arista and VMware security advisories for further guidance.
CVSS
10
Vendor
Arista Networks
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
VeloCloud Orchestrator
Mitigation
Apply the latest security patches released by Arista and VMware for VeloCloud Orchestrator immediately. If patching is not immediately possible, consider disabling certificate-based Edge authentication, noting this will impact Edge connectivity. Monitor Arista and VMware security advisories for further guidance.
Arista and VMware have confirmed active exploitation of CVE-2026-93952, a critical vulnerability in on-premises VeloCloud Orchestrator (VCO). The flaw allows a remote attacker with no login access to privilege internal functions and affect the VCO host. Only VCO deployments configured to authenticate Edge devices using certificates are affected. A CVSS score of 10.0 has been assigned. Patches have been released; organizations are urged to update immediately.