Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
Arista VeloCloud Orchestrator (VCO) on-premises deployments contain an improper input validation flaw that allows a remote attacker to reach privileged internal functionality without authorization. Successful exploitation can fully compromise the orchestrator, affecting the confidentiality, integrity, and availability of both the VCO host and all network data it manages. Versions through 5.2.3.15, 6.1.3.7, 6.4.2.7, and 7.0.0.2 are affected; hosted and dedicated VCO instances were patched separately by Arista.
Improper input validation (CWE-20) occurs when an application fails to enforce adequate checks on attacker-supplied data before passing it to internal processing logic. In VeloCloud Orchestrator, the flaw exists on a network-accessible interface where the orchestrator does not sufficiently validate incoming requests. This allows crafted input to bypass the validation boundary and reach internal functionality that should be restricted to privileged operations. Because the orchestrator manages SD-WAN edge devices and the policies governing them, the attack surface is significant: any network-reachable instance is potentially exposed.
An attacker sends crafted requests to the VCO's network-accessible interface. The CVSS vector rates the attack as requiring no privileges, although the advisory does not explicitly confirm unauthenticated access, and the attack carries some complexity, suggesting specific input construction is required to bypass validation gates. If successful, the attacker gains access to privileged internal functionality of the VCO host, with potential full impact on confidentiality, integrity, and availability of the orchestrator and all data it manages. The precondition is an on-premises deployment reachable from the attacker's network position; hosted and dedicated instances were already remediated by Arista before public disclosure.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Arista VeloCloud Orchestrator runs inside your authorization boundary, yes. CVE-2026-93952 appears on CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of September 25, 2026 has already passed. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding. An overdue one is a finding your assessor and sponsoring agency can see right now. You either remediate it or formally document the mitigation and the delay.
Knox does not patch your software. Remediating Arista VeloCloud Orchestrator is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage that support documentation of the fix for your next assessment. The remediation work is yours to carry out; maintaining a defensible compliance posture while you do it is not something you manage alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-93952 surfaces, exposure appears during ongoing monitoring rather than waiting until an assessor flags it at review time. That gap between disclosure and discovery is where risk lives, and continuous monitoring closes it.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
An unremediated CVE-2026-93952 is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding out now and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship on solid ground.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.









_Horizontal_RGB.png)








