Arista Networks Patches Actively Exploited Zero-Day in VeloCloud Orchestrator On-Prem
Critical vulnerability affects on-premises deployments; exploitation confirmed prior to patch release

Key Takeaways
- Arista Networks released patches for a zero-day vulnerability actively exploited in the wild.
- The flaw affects VeloCloud Orchestrator On-Prem deployments.
- Specific exploitation details and a CVE identifier were not provided in the source summary.
- Successful exploitation could allow unauthorized access or control over the affected system.
- Users should apply the available security patches immediately to mitigate the risk.
Quick answers
- What happened?
- Arista Networks has released security patches to address a zero-day vulnerability that is being actively exploited in the wild. The flaw impacts VeloCloud Orchestrator (VCO) On-Prem deployments. While specific technical details regarding the CVE identifier and exploitation methodology were not disclosed in the source summary, the company confirmed that patches are now available to mitigate the risk.
- Which products are affected?
- VeloCloud Orchestrator On-Prem
- What should defenders do?
- Apply the security patches released by Arista Networks for VeloCloud Orchestrator On-Prem as soon as possible. Monitor Arista Networks security advisories for additional details regarding the vulnerability and verification of patch applicability.
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. The vulnerability was confirmed to be exploited in the wild prior to the patch release, though the summary did not specify the exact nature of the impact, such as data exfiltration or system disruption. The company has not assigned a CVE ID to the flaw in the provided data. Successful exploitation could allow unauthorized access or control over the affected VCO On-Prem system. Arista Networks has issued security updates to address the vulnerability. Users of VeloCloud Orchestrator On-Prem are strongly advised to apply the available patches as soon as possible to reduce the risk of exploitation. The advisory was reported by BleepingComputer on 2026-09-23.
Security Details
A zero-day vulnerability affecting VeloCloud Orchestrator On-Prem is being actively exploited in the wild. Arista Networks has released security patches to address the flaw. The summary did not specify the CVE ID, exploitation vector, or precise impact such as data exfiltration or system disruption. Successful exploitation could allow unauthorized access or control over the affected VCO On-Prem system.
Affected products
VeloCloud Orchestrator On-Prem
Mitigation
Apply the security patches released by Arista Networks for VeloCloud Orchestrator On-Prem as soon as possible. Monitor Arista Networks security advisories for additional details regarding the vulnerability and verification of patch applicability.
Sources
BleepingComputer
Arista patches actively exploited VeloCloud Orchestrator zero-day
Sep 23, 2026 · 12:29
Original link
Related Security News

Hackers exploit Citrix NetScaler zero-day to deploy web shells
Cybersecurity firms report that attackers are exploiting a zero-day vulnerability in Citrix NetScaler to deploy custom web shells and tunneling malware. The exploitation grants root access, enables credential theft, and facilitates lateral movement into internal networks. Citrix has released patches and security advisories addressing CVE-2026-88772.



