Arista Networks security advisory (AV26-947)

Serial number: AV26-947
Date: September 22, 2026

As of September 22, 2026, Arista Networks is affected by a vulnerability in the following product:

  • VeloCloud Orchestrator (VCO) On-Prem
    • Versions 5.2.0 to 5.2.3.15
    • Versions 6.1.0 to 6.1.3.7
    • Versions 6.4.0 to 6.4.2.7
    • Versions 7.0.0 to 7.0.0.2

Open-source reporting indicates that CVE-2026-93952 is being exploited in the wild.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Date modified: