CVE-2026-93952 is a maximum-severity (CVSS 3.1 base 10.0) improper input validation flaw (CWE-20) in the on-premises edition of Arista’s VeloCloud Orchestrator, used to manage VeloCloud SD-WAN deployments. CISA added it to the Known Exploited Vulnerabilities catalog on September 22, 2026 — the same day the CVE record was published — and VulnCheck’s KEV feed carries the same exploitation status and date.
Only self-hosted orchestrators need action from their operators. The CVE record states that hosted VCO instances, including Dedicated ones, were affected and have already been patched.
What the flaw is
The CVE record describes a weakness that may let a remote attacker reach privileged internal functionality of the orchestrator and affect the underlying VCO host. It names confidentiality, integrity and availability of both the orchestrator and the data it manages as at risk. It does not say which interface or request path is involved; Arista Security Advisory 0183 is the authoritative technical source and the place to find affected and fixed versions.
The CVSS vector explains the 10.0: network-reachable, low attack complexity, no privileges, no user interaction, and a changed scope (S:C). A changed-scope rating means NVD scores the impact as reaching beyond the vulnerable component itself; the CVE record names the VCO host and the data the orchestrator manages as affected.
Evidence and confidence
- High confidence — exploitation status, reported independently by CISA KEV and VulnCheck KEV, both dated September 22, 2026.
- High confidence — the CWE-20 classification, which NVD, CVE.org, CISA KEV and VulnCheck all agree on.
- Medium confidence — the 10.0 score and vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), which come from NVD alone in our ingestion. - Not yet available — no FIRST EPSS score is in our ingestion for this CVE yet.
No field is in conflict across our sources. Our source data does not carry a fixed-version field.
Why this matters
CISA listing is the deciding fact here, not the score. This CVE is both maximum-severity and confirmed exploited, so on-prem VCO instances belong at the front of the patch queue. The CVE record puts the orchestrator’s own data, not just the host, within the impact.
CISA KEV listing also puts this CVE under Binding Operational Directive 26-04 for in-scope federal agencies. CISA’s catalog entry additionally points to its Forensics Triage Requirements, so treat an unpatched internet-reachable orchestrator as a system to check for compromise, not only one to update.
Frequently Asked Questions
What is CVE-2026-93952? A CVSS 10.0 improper input validation vulnerability (CWE-20) in on-premises Arista VeloCloud Orchestrator that may let a remote attacker (no privileges required, per NVD’s CVSS vector) reach privileged internal functionality and affect the VCO host.
Is CVE-2026-93952 being actively exploited? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on September 22, 2026, and VulnCheck’s KEV feed reports the same.
Do Arista-hosted VeloCloud customers need to do anything? Not for patching, according to the CVE record, which states hosted and Dedicated VCO instances were affected and have already been patched. On-prem operators must apply Arista’s fix themselves.
Does this create a federal patching deadline? Yes. CISA KEV listing means Binding Operational Directive 26-04’s remediation timeline applies to in-scope federal agencies.
Which version fixes CVE-2026-93952? Our source data does not carry a fixed-version field. Arista Security Advisory 0183 lists affected and remediated releases.
Severity, vector and weakness classification from the National Vulnerability Database record for CVE-2026-93952, with description and hosted-instance status from the CVE.org record. Exploitation status and the September 22, 2026 catalog date from CISA’s Known Exploited Vulnerabilities catalog entry, independently corroborated by VulnCheck KEV. Vendor advisory: Arista Security Advisory 0183. Aggregated September 24, 2026. See more vulnerability intelligence.