# Arista patches exploited VeloCloud management flaw as more fixes remain pending

_Published Wednesday, September 23, 2026 at 10:53 AM EDT · Security, Infrastructure · Latest · Tier 2 — Notable_

![Arista patches exploited VeloCloud management flaw as more fixes remain pending — Primary](https://www.bleepstatic.com/content/hl-images/2026/09/23/Arista-logo.jpg)

Arista Networks has released patches for an actively exploited flaw affecting VeloCloud Orchestrator deployments that use certificate-based authentication with edge devices. The flaw, CVE-2026-93952, can let remote attackers reach privileged functions on the management host if they have access to the web interface and the public portion of an edge authentication certificate.

Arista says it has patched hosted deployments on specified versions and plans fixes for older affected versions. The US Cybersecurity and Infrastructure Security Agency added the flaw to its known exploited vulnerabilities catalog and ordered federal civilian agencies to secure their networks by Friday, September 25.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/arista-patches-actively-exploited-velocloud-orchestrator-zero-day/)

---
Canonical: https://techandbusiness.org/newswire/K9gu-yyXH5psMNMp6fIcj_
Published: 2026-09-23T14:53:26.542Z
Story chronology: 2026-09-23T12:29:53.000Z
Retrieved: 2026-09-23T16:47:15.590Z
Publisher: Tech & Business (techandbusiness.org)
