Arista Product Security Update Advisory (CVE-2026-93952)

Arista Product Security Update Advisory (CVE-2026-93952)
  • A security update addressing a vulnerability discovered in Arista products has been released.
  • The affected product is VeloCloud Orchestrator (VCO) On-Prem.
  • Affected Versions are 5.2.3.15 And earlier, 6.1.3.7 And earlier, 6.4.2.7 And earlier, and 7.0.0.2 And earlier.
  • CVE-2026-93952 is a vulnerability that allows an unauthenticated remote threat actor (an external threat actor who is not logged in) to access internal functions requiring privileges, potentially affecting VCO hosts.
  • The patch was provided through the latest update.
  • The fixed versions are VeloCloud Orchestrator (VCO) 5.2.3.16 And 6.4.2.8.
  • Arista has advised users to update to the latest version with the Vulnerability Patch in accordance with the instructions on the reference site.