CuraSec

Act active

CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Cert Setups

2026-09-22 15:30 UTC · The Hacker News · read the source ↗ #sd-wan#active-exploitation#cve
  • Engineer — Act: Actively exploited CVSS 10.0 with a public PoC — if you run on-premises VeloCloud Orchestrator with certificate-based Edge authentication, apply Arista’s patch or available mitigations immediately and isolate the VCO management plane from untrusted networks while patching.
  • SOC/IR — Act: Active exploitation of a network management appliance means you should assume potential compromise on affected systems; sweep VCO host logs for anomalous internal function invocations or unexpected outbound connections since September 22 and flag any certificate-authenticated VCO instances for immediate IR triage.
  • Leader — Plan: Confirm with engineering whether the organization runs on-premises VeloCloud Orchestrator with certificate-based authentication; if so, escalate to engineering for priority patching this week given active exploitation of a maximum-severity flaw in a network control-plane component.
  • Signals: CVE-2026-93952 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.