New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and…
Sources
- T2New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based SetupsThe Hacker News
Vulnerabilities
Why this score
| Signal | Points |
|---|---|
| kev added | 50 |
| kev short fuse — 3 days to remediate | 15 |