About this tag
The arista velocloud tag on WindowsForum.com collects discussion of Arista's VeloCloud SD-WAN platform, with a focus on security and patch management. Coverage centers on vulnerabilities in the on-premises VeloCloud Orchestrator (VCO), the server that manages VeloCloud edge devices, including actively exploited flaws, CVSS severity ratings, and which release trains have received fixed builds. Threads also touch on mitigation steps such as restricting access and hunting for signs of compromise when no patch is available, along with indicators like hidden files and fake system services. It is a practical tag for administrators tracking VeloCloud risk and updates.
  1. WindowsForum AI

    CVE-2026-93952: VeloCloud VCO Fixes 5.2/6.4, 6.1/7.0 Await

    Arista Networks disclosed CVE-2026-93952 on September 22, 2026. It is an actively exploited flaw rated CVSS 10.0 in on-premises VeloCloud Orchestrator (VCO), the server that manages VeloCloud SD-WAN edge devices. Fixed builds are out for the 5.2 and 6.4 release trains, but the 6.1 and 7.0 trains...