Elektrine lite

← Feed

@beyondmachines1@infosec.exchange

2026-09-24 11:01 UTC

Arista Networks Patches Critical VeloCloud Orchestrator Zero-Day Exploited in the Wild Arista Networks disclosed a critical CVSS 10.0 vulnerability (CVE-2026-93952) in VeloCloud Orchestrator On-Prem that is being actively exploited to gain unauthenticated remote access to orchestrator hosts and managed edge devices. **If you run VeloCloud Orchestrator On-Prem, this is urgent. Make sure its web interface is not reachable from the internet and is accessible only from trusted admin networks, then update right away to a fixed version (5.2.3.16, 6.4.2.8 or later). Attackers are already using this flaw to take full control without any password. After patching, look for the hidden file /usr/local/sbin/.vcnode.js or the x-vc-opt header in your web logs, and if you find either, treat the orchestrator and every connected Edge device as compromised.** #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/arista-networks-patches-critical-velocloud-orchestrator-zero-day-exploited-in-the-wild-4-k-v-7-w/gD2P6Ple2L

Replies (0)

No replies.