peter bassill · operator
$ cve CVE-2026-93952 JSON

CVE-2026-93952 KEV

10.0
CRITICAL · CVSS 3.1 · EPSS 0.9% (pctl 58)

Patch first

On CISA KEV — known exploited in the wild, due 2026-09-25.

Description

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS0.9% — more likely to be exploited than 58% of all CVEs
WeaknessCWE-20
On CISA KEVyes — remediate by 2026-09-25
Public exploitnone known
Published2026-09-22
Last modified2026-09-23

CISA KEV

NameArista VeloCloud Orchestrator Improper Input Validation Vulnerability
Added2026-09-22
Due2026-09-25
Vendor / productArista / VeloCloud Orchestrator
Ransomware usenone reported

Affected (1)

VendorProduct
aristavelocloud orchestrator

References

→ the Explorer  ·  watch your stack  ·  NVD