CuraSec

Act active

Arista patches actively exploited VeloCloud Orchestrator zero-day

2026-09-23 15:27 UTC · BleepingComputer · read the source ↗ #zero-day#velocloud#sd-wan
  • Engineer — Act: VeloCloud Orchestrator On-Prem is actively exploited network management infrastructure — apply Arista’s released patches immediately and treat all unpatched VCO instances as potentially compromised.
  • SOC/IR — Act: Active exploitation means systems may have been compromised before patches were available — sweep VCO On-Prem hosts for anomalous admin activity, lateral movement, and configuration changes since the zero-day window opened.
  • Leader — Act: Actively exploited zero-day in SD-WAN management infrastructure warrants same-week action — confirm whether VCO On-Prem is deployed, verify the patch has been applied or is on an emergency timeline, and brief IT leadership on exposure status.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.