CVE-2026-93952
- CVSS
- —
- EPSS
- —
- CISA KEV
- Added 2026-09-22, due 2026-09-25
- Exploitation
- No report
- Public exploits
- None seen
- State
- Unknown
Coverage

Actively exploitedThe Hacker News
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups(opens the publisher's site in a new tab)
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and…
What we observed
- kev addedcisa-kev