CVE-2026-93952
As of September 22, 2026, Arista Networks is affected by a vulnerability in the following product: VeloCloud Orchestrator (VCO) On-Prem Versions 5.2.0 to 5.2.3.15 Versions 6.1.0 to 6.1.3.7 Versions 6.4.0 to 6.4.2.7 Versions 7.0.0 to 7.0.0.2 Update 1 On September 22, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-93952 to their Known Exploited Vulnerabilities (KEV) Database. Open-source reporting indicates that CVE-2026-93952 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
EPSS 0.42% · 36.3th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Versions | Versions 6.1.0 to 6.1.3.7 | |
| Versions | Versions 7.0.0 to 7.0.0.2 | |
| Versions | Versions 6.4.0 to 6.4.2.7 | |
| Versions | Versions 5.2.0 to 5.2.3.15 |
Timeline
- Sep 22, 2026 CISA KEV Added
- Sep 22, 2026 VulnCheck KEV Exploitation
- Sep 22, 2026 EPSS Score
- Sep 22, 2026 Coalition ESS Score
- Sep 22, 2026 CVE Published
- Sep 23, 2026 CVE Updated
References
- https://cyber.gc.ca/en/alerts-advisories/arista-networks-security-advisory-av26-947 advisory
- https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183 vendor
- https://www.arista.com/en/support/advisories-notices vendor
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93952 advisory