VDB

CVE-2026-93952

CVE-2026-93952 PUBLISHED KEV CVSS 8.600000381469727 HIGH

As of September 22, 2026, Arista Networks is affected by a vulnerability in the following product: VeloCloud Orchestrator (VCO) On-Prem Versions 5.2.0 to 5.2.3.15 Versions 6.1.0 to 6.1.3.7 Versions 6.4.0 to 6.4.2.7 Versions 7.0.0 to 7.0.0.2 Update 1 On September 22, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-93952 to their Known Exploited Vulnerabilities (KEV) Database. Open-source reporting indicates that CVE-2026-93952 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

EPSS 0.42% · 36.3th percentile

Risk Scores

CVSS 4.0
8.600000381469727
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.42%
36.3th percentile

Affected Products

VendorProductVersions
VersionsVersions 6.1.0 to 6.1.3.7
VersionsVersions 7.0.0 to 7.0.0.2
VersionsVersions 6.4.0 to 6.4.2.7
VersionsVersions 5.2.0 to 5.2.3.15

Timeline

  • Sep 22, 2026 CISA KEV Added
  • Sep 22, 2026 VulnCheck KEV Exploitation
  • Sep 22, 2026 EPSS Score
  • Sep 22, 2026 Coalition ESS Score
  • Sep 22, 2026 CVE Published
  • Sep 23, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›