VDB

GCVE-110-NCSC-2026-385

GCVE-110-NCSC-2026-385
Advisory PublishedCVSS 10.0/10
Vulnetix · Advisory published September 22, 2026
A remote vulnerability in VeloCloud Orchestrator (VCO) on-prem enables attackers to access privileged internal functions, with operators advised to monitor web access, backend, and system logs for suspicious activity and preserve evidence if compromise is suspected.

Risk Scores

CVSS 3.1
10.0/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Arista Networksvers:unknown/*
Aristavers:unknown/*

References

advisory
advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›