zero-day • BleepingComputer

Arista korjaa aktiivisesti hyväksikäytetyn zero-day-haavoittuvuuden VeloCloud Orchestratorissa — CVE-2026-93952

CVE-2026-93952 Arista VeloCloud Orchestratorissa hyväksikäytetään aktiivisesti ja vaatii vain verkkoyhteyden web-käyttöliittymään sekä Edge-todennussertifikaatin julkisen osan. CISA-määräaika 25. syyskuuta; estä IoC-IP-osoitteet heti.

Arista korjaa aktiivisesti hyväksikäytetyn zero-day-haavoittuvuuden VeloCloud Orchestratorissa — CVE-2026-93952

Arista Networks released an emergency patch on September 24, 2026, for CVE-2026-93952, a maximum-severity flaw in VeloCloud Orchestrator (VCO) already under active exploitation. The bug — improper input validation — primarily affects on-premise VCO deployments where certificate-based authentication between Edge appliances and the orchestrator is enabled. Unlike many SD-WAN vulnerabilities, neither tenant nor operator credentials are required: attackers need network reachability to the VCO web UI and access to the public portion of an Edge device's authentication certificate.

VeloCloud Orchestrator acts as the central brain of Arista's SD-WAN stack: it provisions policies, monitors links, and authenticates Edge routers. When certificate-based Edge→VCO authentication is configured, the platform assumes incoming data is validated correctly. CVE-2026-93952 breaks that assumption and can grant attackers administrative control over the orchestrator without valid user accounts — with direct impact on routing, segmentation, and potential lateral movement into connected branch sites.

Arista has patched hosted VCO environments to version 5.2.3.16 and later or 6.4.2.8 and later. Customers on older on-prem releases — 6.1.3.7 and below and 7.0.0.2 and below — await forthcoming fixes and should treat systems as high risk until then. CISA added the vulnerability to its KEV catalog with a September 25, 2026 deadline, alongside other urgent network product flaws the same week.

Security teams should immediately block IP addresses 142.93.149.77 and 104.248.126.159, identified as compromise indicators. Review nginx logs for the HTTP header `x-vc-opt`, observed in traffic against vulnerable orchestrators. If compromise is suspected, preserve logs and memory images before remediation — VCO generates valuable Edge event metadata that can vanish during reboot or rushed patching.

Arista handled related zero-days earlier in 2026: CVE-2026-7473 in May and CVE-2026-16812 in July. The pattern — emergency patches after confirmed exploitation in critical network infrastructure — underscores that SD-WAN platforms have become priority targets for actors seeking broad network access without phishing individual users.

For Nordic organizations with branches, logistics hubs, and production sites behind VeloCloud, a compromised orchestrator can mean manipulated traffic rules, VPN tunnel interception, or malware pushed to Edge appliances. It is an infrastructure attack with high blast radius even though the exploit technically requires relatively limited prerequisites.

Operators should also audit whether Edge certificate public keys were exposed in internal documents, support tickets, or version control — Arista's advisory states the public certificate portion alone satisfies a prerequisite. Segment VCO administration onto dedicated management VLANs and require jump-host access until patching is verified.

Evidence Rail

  • Confirmed: Arista security bulletin; active in-the-wild exploitation; CISA KEV with September 25 deadline; hosted VCO patched at 5.2.3.16+ and 6.4.2.8+.
  • Reported: IoC IPs 142.93.149.77 and 104.248.126.159; nginx header `x-vc-opt` in attack traffic.
  • Unconfirmed: Full attack chain details and whether tenant data was exfiltrated in known incidents.

Concrete steps for IT and security leaders

1. Identify all VCO instances (hosted and on-prem) and map certificate-based Edge authentication. 2. Apply available patches; isolate on-prem systems awaiting fixes from internet and internal client networks. 3. Block IoC IPs and hunt nginx logs for `x-vc-opt`. 4. Preserve logs before reboot if compromise is suspected; engage DFIR early. 5. Plan Edge certificate rotation after patching and verify no unauthorized policy changes occurred.

In Brief

  • Maximum severity in VCO with certificate-based Edge auth; no tenant login required to exploit.
  • Hosted environments patched; older on-prem awaiting fixes — treat as acute risk.
  • Block 142.93.149.77 and 104.248.126.159; CISA deadline September 25.

Lähteet ja viitteet

← Kaikki uutiset Työkalut