Arista Networks has confirmed that attackers are actively exploiting a critical, zero-authentication flaw in its on-premises VeloCloud Orchestrator (VCO), a vulnerability that paradoxically turns a core security feature into the attack vector. The vulnerability, assigned a maximum CVSS score of 10.0, is tracked as CVE-2026-93952 and represents a severe risk for enterprises using certificate-based authentication for their SD-WAN edge devices.

Flaw Allows Unauthenticated Takeover of SD-WAN Management

VCO is the central server responsible for provisioning, managing, and configuring all VeloCloud SD-WAN Edge devices across an organization's network. Arista disclosed the active exploitation on September 22, confirming that a remote attacker with no valid credentials can exploit the flaw to invoke internal functions on the VCO host.

Successful exploitation grants an attacker administrative control over the orchestrator. From this vantage point, an adversary could reconfigure routing policies across the entire SD-WAN fabric, intercept sensitive traffic flowing between sites, or use the compromised server as a pivot point to move deeper into the corporate network.

The Security Feature Becomes the Vulnerability

The most striking aspect of this incident is that it specifically targets deployments using digital certificate-based authentication for Edge devices—a method widely adopted to strengthen device identity and prevent unauthorized connections. The configuration meant to harden security is the precise condition required to trigger the flaw.

This creates a difficult dilemma for administrators, as the most secure authentication method becomes the most vulnerable one until the issue is resolved.

Immediate Mitigation and Patching Required

Arista has released a patch to remediate CVE-2026-93952. All organizations operating on-premises VCO instances should apply the update as a top-priority emergency change.

For environments where immediate patching is not operationally feasible, Arista recommends a clear interim mitigation: switch the Edge device authentication method from certificate-based to a pre-shared secret. This action removes the vulnerable attack surface while the patch undergoes testing and deployment.

Following patch application, Arista advises administrators to perform a post-remediation audit, reviewing configuration and logs to confirm the fix is in place and to check for any signs of prior unauthorized activity.

Part of a Growing Trend Targeting Central Control

This vulnerability is part of a clear and escalating pattern in the threat landscape: attackers are increasingly targeting centralized management platforms. Rather than compromising individual network appliances one by one, attackers seek a single, high-value entry point—an orchestrator, controller, or management console—that provides broad access to an entire infrastructure domain.

Similar vulnerabilities in other SD-WAN and network management products have made headlines in recent years. This latest incident serves as a stark reminder that the systems designed to simplify and secure network operations can, if vulnerable, become the single most dangerous point of failure. For network administrators, rigorous and timely patch management for these central platforms is no longer optional—it is essential.


Arista Networks 已確認攻擊者正積極利用其本地部署的 VeloCloud Orchestrator (VCO) 中的一個關鍵零認證漏洞,此漏洞矛盾地將一個核心安全功能轉化為攻擊媒介。該漏洞獲得了最高 CVSS 評分 10.0,編號為 CVE-2026-93952,對使用證書認證的 SD-WAN 邊緣設備的企業構成嚴重風險。

漏洞允許未經認證接管 SD-WAN 管理

VCO 是負責對整個組織網絡中所有 VeloCloud SD-WAN 邊緣設備進行 Provisioning、管理和配置的核心伺服器。Arista 於 9 月 22 日披露了此_active exploitation_,確認無有效憑證的遠端攻擊者可利用此漏洞在 VCO 主機上調用內部函數。

成功利用可讓攻擊者獲得對 Orchestrator 的管理控制權。藉此,攻擊者可重新配置整個 SD-WAN 網狀網絡的路由策略、攔截站點間傳輸的敏感流量,或利用被入侵的伺服器作為樞紐點,進一步滲透企業內部網絡。

安全功能成為漏洞

此事件最引人注目之處在於,它專門針對使用數位證書認證的邊緣設備部署——這是一種被廣泛採用以加強設備身份驗證並防止未經授權連接的方法。旨在強化安全性的配置,恰恰是觸發此漏洞的必要條件。

這給管理員帶來了兩難困境:在問題解決之前,最安全的認證方法反而變得最容易受到攻擊。

需立即進行緩解與修補

Arista 已發布補丁修復 CVE-2026-93952。所有運行本地 VCO 實例的組織應將應用此更新作為最優先的緊急變更。

對於無法立即進行補丁操作的環境,Arista 建議了一個明確的過渡緩解方案:將邊緣設備認證方法從基於證書切換為預共享密鑰。此操作可移除易受攻擊的攻擊面,同時等待補丁的測試和部署。

補丁應用後,Arista 建議管理員執行修復後審計,檢查配置和日誌以確認修補到位,並檢查是否有先前未經授權活動的跡象。

鎖定中央控制的趨勢日益增長

此漏洞是威脅領域中一個明確且升級模式的一部分:攻擊者正越來越多地鎖定集中管理平台。攻擊者並非逐一入侵個別網絡設備,而是尋找一個能提供廣泛基礎設施領域訪問權限的高價值單一入口點——一個 Orchestrator、Controller 或管理控制台。

近年來,其他 SD-WAN 和網絡管理產品中的類似漏洞已多次成為頭條新聞。這次最新事件嚴峻提醒我們,旨在簡化和保護網絡營運的系統,若存在漏洞,可能成為最危險的單點故障。對網絡管理員而言,對這些中央平台進行嚴格且及時的補丁管理不再是可選項——而是必不可少。

新聞來源 / Original News Source