Critical Flaw in Arista Networking Software Is Being Actively Exploited, Third Such Bug This Year
Federal agencies face a Friday deadline to patch a maximum-severity vulnerability in software that manages corporate networks, as hackers exploit it before many organizations have installed the fix.
Arista Networks disclosed this week that hackers are actively exploiting a maximum-severity vulnerability in software used to manage corporate wide-area networks, prompting the U.S. Cybersecurity and Infrastructure Security Agency to order federal agencies to patch it by Friday. The flaw affects on-premises deployments of VeloCloud Orchestrator, the server software that controls VeloCloud "edge" devices routing traffic for businesses that use Arista's software-defined networking products.
In a security advisory published September 22, Arista said the vulnerability, tracked as CVE-2026-93952, is an improper input validation flaw that lets a remote attacker access privileged internal functionality on the orchestrator without needing any login credentials. The company rated it 10.0 out of 10 on the industry's severity scale, the maximum possible score, and said the issue "was discovered externally and is known to be actively exploited." Successful exploitation can compromise the confidentiality, integrity and availability of both the orchestrator and the network data it manages.
The vulnerability applies only to orchestrators configured to authenticate their edge devices using digital certificates, a common setup in enterprise deployments. An attacker who obtains the public portion of an edge device's authentication certificate and has network access to the orchestrator's web interface can exploit the flaw without any operator or tenant password. Arista has already patched its own hosted and dedicated cloud versions of the software. For customers running the software themselves, fixed releases are available for the 5.2.x and 6.4.x version lines, but patches for the 6.1.x and 7.0.x lines were still pending as of this week. Arista told customers to restrict access to the orchestrator's web interface to trusted administrative networks and gave administrators two IP addresses tied to malicious activity to check their logs against.
The Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on September 22, one of four vulnerabilities added that day alongside bugs in Check Point and F5 products. Under a binding directive covering federal civilian agencies, the listing gives agencies until September 25 to apply the fix or stop using the affected systems. CISA said such vulnerabilities are "a frequent attack vector for malicious cyber actors" and urged private-sector organizations, which face no legal deadline, to treat the catalog listing with similar urgency.
A pattern of exploitation
Security researchers noted this is the third VeloCloud Orchestrator vulnerability Arista has confirmed under active attack in 2026, following flaws disclosed in May and July, according to reporting by BleepingComputer. The repeated targeting reflects a broader shift among ransomware and espionage-linked hacking groups toward network-management "orchestrator" software, which sits at a single control point capable of reconfiguring traffic across dozens or hundreds of connected business locations at once. SecurityWeek and The Hacker News both reported that the flaw requires no authentication at all in qualifying configurations, making it especially attractive to opportunistic scanning by criminal groups.
Arista did not say how many customers run vulnerable on-premises versions or identify the attackers behind the exploitation. The company acquired VeloCloud, a software-defined wide-area networking specialist, from Broadcom in 2025, folding it into its enterprise networking portfolio. For businesses that rely on the software to connect branch offices, warehouses and retail locations to central networks, an unpatched orchestrator represents a single point of failure: compromising it could let an attacker see or redirect traffic across an entire corporate network rather than a single device.

UN Security Council holds first session on AI loss-of-control risk as rival CEOs urge global rules

Meta Bets Big on Wearables, Unveiling $1,299 Mixed-Reality Glasses and a Cheaper AI Eyewear Lineup

ASML Says It Sold Zero Chipmaking Machines to European Customers Last Quarter
