A Hidden Danger Just Surfaced in Your SD-WAN Setup
Emily Davis ·
Listen to this article~5 min
A critical new flaw (CVE-2026-93952) in VeloCloud Orchestrator is under active attack, allowing remote privilege escalation without login in certificate-based SD-WAN setups.
If you're using a VeloCloud SD-WAN, there's a critical new alert you need to know about. It's one of those vulnerabilities that sounds technical at first, but the real-world impact is anything but. Let's break it down in plain English.
Arista issued a warning on September 22nd. Attackers are actively exploiting a fresh flaw in on-premises VeloCloud Orchestrator, or VCO for short. Think of the VCO as the brain of the whole operation—it's the server that manages all the Edge devices in the SD-WAN network.
### What Exactly Is Happening?
The flaw has a name: CVE-2026-93952. In security speak, it's a whopper, scoring a CVSS 10.0—the highest severity rating possible. Here's the scary part: a remote attacker, without any login credentials, could potentially gain elevated privileges to internal functions. That means they could start affecting the VCO host itself.
But there's a crucial detail that makes this a targeted threat. This exploit only works on orchestrators configured to authenticate their Edge devices using certificates. If your setup uses a different method, you might be in the clear for now, but that's no reason to relax.
### Why This Flaw Is a Big Deal
It turns a foundational component of your network infrastructure into a potential weak spot. The VCO is supposed to be your command center, your secure hub. A breach here doesn't just affect one device; it can ripple out to the entire network it manages. We're talking about the integrity of your wide-area network, which for many businesses is the backbone of their daily operations.
- **Remote Access Without Login:** The 'no login required' aspect is particularly alarming. It lowers the barrier for entry for attackers significantly.
- **Privilege Escalation:** Gaining internal privileges means an attacker could move from a minor foothold to controlling critical functions.
- **Certificate-Based Vulnerability:** This targets a specific, often trusted, security method, which can catch teams off guard.
It's a stark reminder that even the most trusted systems and authentication methods need constant scrutiny.
### What You Should Do Right Now
First, don't panic. Awareness is the first step. If you manage a VeloCloud SD-WAN, your immediate action should be to confirm your VCO's authentication setup. Are you using certificate-based authentication for your Edges?
If the answer is yes, you need to prioritize this. Check with Arista for any available patches or security advisories specific to CVE-2026-93952. The fact that it's already being actively exploited means time is of the essence. This isn't a theoretical risk; it's a live one.
Consider this a wake-up call for your broader security posture. When a critical vulnerability like this appears, it's a good moment to ask bigger questions. Are your monitoring tools sharp enough to detect unusual activity on your VCO? When was the last time you reviewed your SD-WAN security configuration?
One security expert I respect often says, *'Complexity is the enemy of security.'* This flaw lives in that complex intersection of orchestration software and certificate management. Simplifying and understanding those layers is part of the long-term defense.
### Looking Beyond the Immediate Fix
Patching this specific flaw is job number one. But the lesson goes deeper. It highlights how critical infrastructure management points—like orchestrators—are prime targets. They offer maximum impact for an attacker's effort. Your security strategy must protect not just the endpoints and the data, but the very systems that control the network itself.
Make sure your team is aware of this threat. Review your incident response plan. Does it include scenarios where the management plane of your network is compromised? If not, it might be time to add that chapter. Staying secure isn't about avoiding every single flaw—that's impossible. It's about knowing the landscape, responding swiftly when threats emerge, and building layers of defense so that a single vulnerability doesn't become a catastrophic breach. Your network's brain needs just as much protection as everything else connected to it.