Arista is urging customers to patch an actively exploited VeloCloud Orchestrator flaw rated 10.0, and the build that fixed its July zero day is vulnerable to this one. CVE-2026-93952 is an authentication bypass in the on-premises web interface.
- The version trap. July’s CVE-2026-16812 was fixed in 5.2.3.14. The September flaw affects everything through 5.2.3.15, so those builds carry the July fix and stay exposed. The 6.4 train repeats it.
- No fix at all on two trains. Patches exist for 5.2.3.16 and 6.4.2.8. The 6.1 and 7.0 trains are still waiting, so those operators can only restrict access and hunt.
- The advisory assumes something. Exposure requires the public portion of an edge certificate, and a public key is not secret by design. The CVE classifies it as authentication bypass, not a crypto failure.
- Patching is not remediation. The indicators are a hidden script at .vcnode.js, a daemon named vc-sysmond, and a systemd unit that restarts it. The hotfix closes the door without evicting anyone already inside.
- CISA drew a higher bar. The deadline sits under a directive requiring documented forensic triage, not a change ticket showing the fix applied.
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.
