# WAN

Published articles for WAN.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## On-prem VeloCloud Orchestrator under attack, only some versions patched

DevFeed: [On-prem VeloCloud Orchestrator under attack, only some versions patched](<https://devfeed.tech/articles/on-prem-velocloud-orchestrator-under-attack-only-some-versions-patched-59250.md>)

Original publisher: [Read original article](<https://www.networkworld.com/article/4226139/on-prem-velocloud-orchestrator-under-attack-only-some-versions-patched.html>)

Author: Shweta Sharma

Published: 2026-09-24T13:32:47Z

Content type: news

Language: en

Sources: [Network World](<https://devfeed.tech/sources/network-world.md>)

Topics: [SD-WAN](<https://devfeed.tech/topics/sd-wan.md>), [Security](<https://devfeed.tech/topics/security.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [input](<https://devfeed.tech/topics/input.md>), [public key](<https://devfeed.tech/topics/public-key.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [on-prem](<https://devfeed.tech/topics/on-prem.md>)

Tags: [actively-exploited](<https://devfeed.tech/tags/actively-exploited.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cvss](<https://devfeed.tech/tags/cvss.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [network-security](<https://devfeed.tech/tags/network-security.md>), [network-security-networking-sd-wan-security-wan](<https://devfeed.tech/tags/network-security-networking-sd-wan-security-wan.md>), [networking](<https://devfeed.tech/tags/networking.md>), [on-prem](<https://devfeed.tech/tags/on-prem.md>), [patching](<https://devfeed.tech/tags/patching.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [sd-wan](<https://devfeed.tech/tags/sd-wan.md>), [security](<https://devfeed.tech/tags/security.md>), [velocloud-orchestrator](<https://devfeed.tech/tags/velocloud-orchestrator.md>), [wan](<https://devfeed.tech/tags/wan.md>)

### AI overview

A critical vulnerability in VeloCloud Orchestrator is being actively exploited. The issue affects certain on-premises and other deployments under specific authentication and network conditions; Arista has patched some versions and urges customers to upgrade, while preserving logs before remediation if compromise is suspected.

### Source excerpt

A flaw in VeloCloud Orchestrator enables attackers to access the platform organizations use to manage their VeloCloud SD-WAN subscriptions and the edge devices it controls. Arista, which now owns the VeloCloud business, warned customers that a vulnerable configuration exists in on-premises VeloCloud Orchestrator deployments that remote attackers may abuse to access "privileged internal functionality" and impact the VSO host. The flaw also affected Arista's Hosted and Dedicated VCO deployments, but the company has now patched them. "This issue was discovered externally and is known to be actively exploited," Arista said in its advisory, urging customers to upgrade to a patched release of VCO immediately -- although fixes are currently available only for some of the affected versions. Mayuresh Dani, security research manager, at Qualys Threat Research Unit, warned that unpatched versions remain "exposed to active exploitation and have only compensating controls as a protection." Arista said that organizations suspecting compromise should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible. Andrew Costis, engineering manager of the adversary research team at AttackIQ, backs that advice. "Patching closes the door but doesn't reverse what came through it. A compromised orchestrator can reach the Edge devices it manages, rotate credentials and validate device state across sites," he said. Exploitation limited to a configuration Arista is tracking the flaw as CVE-2026-93952, an improper input validation issue with a critical CVSS rating of 10.0. An attack will only work under certain conditions, though: A VCO deployment is exposed only if certificate-based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured, and the attacker has the public key of the VeloCloud Edge authentication certificate and also network access to the VCO w