A significant vulnerability, tracked as CVE-2026-93952, has been identified in the VeloCloud Orchestrator (VCO), which is critical for managing Edge devices within VeloCloud's SD-WAN solutions. Disclosed by Arista Networks on September 22, this flaw allows remote attackers to exploit internal functions without requiring login credentials, specifically in setups that employ certificate authentication for Edges. The severity of this vulnerability is underscored by its CVSS score of 10.0, indicating a critical risk to affected systems.
For businesses using VeloCloud Orchestrator, this vulnerability necessitates immediate attention and response. Organizations must assess their current configurations to determine if they are susceptible and implement necessary security measures, such as updating to patched versions or modifying authentication methods. The implications of this exploit extend beyond the immediate threat; they highlight the broader risks associated with certificate-based setups in network management, emphasizing the need for robust cybersecurity practices in the deployment of AI and connectivity solutions. This situation serves as a reminder of the importance of continual vigilance and proactive security measures in the ever-evolving landscape of cybersecurity.
---
*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html)*