CVE-2026-93952CISA KEVEPSS p63.4%

CVE-2026-93952Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

Arista / VeloCloud Orchestrator

Description

Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Scoring

CVSS 10.0 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS1.06% probability of exploitation · percentile 63.4% · 2026-10-05T12:00:23Z
Last modified2026-09-23

CISA KEV entry

Added to KEV: 2026-09-22

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.