Photo by Vitaly Gariev on Unsplash. Source: https://unsplash.com/photos/man-working-on-laptop-in-dimly-lit-office-W8FvUgCLO6U (Unsplash License). A man working at a laptop in a dimly lit office at night.

Arista is urging customers to patch an actively exploited VeloCloud Orchestrator flaw rated 10.0, and the build that fixed its July zero day is vulnerable to this one. CVE-2026-93952 is an authentication bypass in the on-premises web interface.

  • The version trap. July’s CVE-2026-16812 was fixed in 5.2.3.14. The September flaw affects everything through 5.2.3.15, so those builds carry the July fix and stay exposed. The 6.4 train repeats it.
  • No fix at all on two trains. Patches exist for 5.2.3.16 and 6.4.2.8. The 6.1 and 7.0 trains are still waiting, so those operators can only restrict access and hunt.
  • The advisory assumes something. Exposure requires the public portion of an edge certificate, and a public key is not secret by design. The CVE classifies it as authentication bypass, not a crypto failure.
  • Patching is not remediation. The indicators are a hidden script at .vcnode.js, a daemon named vc-sysmond, and a systemd unit that restarts it. The hotfix closes the door without evicting anyone already inside.
  • CISA drew a higher bar. The deadline sits under a directive requiring documented forensic triage, not a change ticket showing the fix applied.

Read the full analysis.

By Ivan Tarin

Ivan Tarin is a Principal Product Marketing Manager at SUSE, where he owns go-to-market strategy and positioning for a seven-product cloud-native portfolio spanning Kubernetes, virtualization, storage, security, and observability. A former full-stack developer who shipped production code for enterprise and public-sector clients including U.S. national laboratories, Ivan translates complex infrastructure and AI technology into messaging that lands with developers, platform teams, and enterprise buyers. He has presented at KubeCon, SUSECON, and AWS Developer Week, and is currently pursuing an MS in Artificial Intelligence at the University of Colorado Boulder.

Leave a Reply

Your email address will not be published. Required fields are marked *

Get the next one before it is old news

Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.