Status: KEV
| Advisory ID: CVE-2026-93952
Key Details
| CVE | CVE-2026-93952 |
| Vulnerability Name | Arista VeloCloud Orchestrator Improper Input Validation Vulnerability |
| Affected products | Arista VeloCloud Orchestrator |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-20 (Improper Input Validation) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-09-22. |
| Exploitation prediction (EPSS) | 0.90% probability of exploitation in the next 30 days (58% percentile) -- FIRST.org's EPSS model. |
| Federal remediation deadline | 2026-09-25 (CISA KEV, Binding Operational Directive). |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
What to Do
Monitor Arista's web page for any future patch releases.
References
KEV Required Action