Arista has disclosed active exploitation of a critical remote code execution vulnerability in VeloCloud Orchestrator (VCO), the central management server for SD-WAN deployments. The flaw, tracked as CVE-2026-93952, carries a CVSS score of 10.0, indicating maximum severity.

The vulnerability allows unauthenticated remote attackers to execute privileged functions on affected VCO hosts without requiring login credentials. Organizations using certificate-based authentication for Edge devices face the highest risk. VeloCloud Orchestrator manages SD-WAN Edge appliances across enterprise networks, making compromise of the VCO server a critical access point for attackers seeking lateral movement and network control.

Arista confirmed active exploitation in the wild on September 22, meaning threat actors have already weaponized this flaw. The combination of unauthenticated access, remote exploitability, and full system compromise potential explains the perfect CVSS rating. Attackers need only network access to the VCO server, typically an on-premises deployment exposed to internal networks or the internet.

SD-WAN infrastructure sits at a network's core, routing traffic between branch offices, data centers, and cloud environments. Compromise of VeloCloud Orchestrator grants attackers control over all connected Edge devices, enabling them to intercept encrypted traffic, inject malicious routes, exfiltrate data, or create persistent backdoors across an organization's entire WAN. The impact extends beyond the VCO server itself to every endpoint managed by that orchestrator.

The vulnerability specifically impacts on-premises VCO deployments using certificate-based authentication for Edge device connections. Organizations relying on username and password authentication may face lower immediate risk, though Arista has not confirmed this distinction publicly. Certificate-based setups represent security-conscious deployments, making this flaw particularly dangerous for organizations that invested in stronger authentication mechanisms.

Exploitation requires no special privileges or pre-existing access, distinguishing this flaw from typical post-compromise escalation vulnerabilities. Attackers can exploit CVE-2026-93952 directly from the network perimeter if the VCO server accepts external connections, or from within compromised internal networks. The lack of authentication requirements and remote access potential make this vulnerability trivial to exploit at scale.

Organizations running VeloCloud Orchestrator on-premises should assume compromise if their deployments were exposed during the active exploitation window. Immediate actions include checking VCO logs for unauthorized administrative access, unusual API calls, or configuration changes. Network teams should isolate affected VCO servers and review all Edge device communications for tampering.

Arista has not publicly released patched VCO versions as of the September 22 disclosure. Organizations must consult Arista's security advisories for patch availability and timelines. Interim mitigation includes network segmentation restricting VCO access to trusted sources, disabling external connectivity if not required, and implementing intrusion detection signatures specific to CVE-2026-93952 exploitation attempts.

The flaw reflects broader risks in SD-WAN management infrastructure. These centralized orchestration platforms represent single points of failure for entire network topologies. Compromise at this layer bypasses perimeter defenses and allows attackers to operate at the WAN backbone level, where detection becomes exponentially harder.