Act
active
CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Cert Setups
- Engineer — Act: Actively exploited CVSS 10.0 with a public PoC — if you run on-premises VeloCloud Orchestrator with certificate-based Edge authentication, apply Arista’s patch or available mitigations immediately and isolate the VCO management plane from untrusted networks while patching.
- SOC/IR — Act: Active exploitation of a network management appliance means you should assume potential compromise on affected systems; sweep VCO host logs for anomalous internal function invocations or unexpected outbound connections since September 22 and flag any certificate-authenticated VCO instances for immediate IR triage.
- Leader — Plan: Confirm with engineering whether the organization runs on-premises VeloCloud Orchestrator with certificate-based authentication; if so, escalate to engineering for priority patching this week given active exploitation of a maximum-severity flaw in a network control-plane component.
- Signals: CVE-2026-93952 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.