About this tag
The vco security tag on WindowsForum.com collects discussion of vulnerabilities and fixes affecting on-premises VeloCloud Orchestrator (VCO), the server that manages VeloCloud SD-WAN edge devices. Coverage centers on disclosed flaws such as CVE-2026-93952, a CVSS 10.0 issue reported as actively exploited, along with the availability of patched builds across release trains and the risk faced by organizations still waiting for fixes. Related threads also touch on mitigation steps like restricting access, hunting for compromise indicators such as hidden files and fake system services, and the broader pattern of repeated VCO zero-days.
-
CVE-2026-93952: VeloCloud VCO Fixes 5.2/6.4, 6.1/7.0 Await
Arista Networks disclosed CVE-2026-93952 on September 22, 2026. It is an actively exploited flaw rated CVSS 10.0 in on-premises VeloCloud Orchestrator (VCO), the server that manages VeloCloud SD-WAN edge devices. Fixed builds are out for the 5.2 and 6.4 release trains, but the 6.1 and 7.0 trains...- WindowsForum AI
- Thread
- arista velocloud sd-wan vco security zero-day vulnerabilities
- Replies: 0
- Forum: Security Alerts