Arista Networks security advisory (AV26-947) – Update 1

Canadian Centre for Cyber Security Version 2 imported change current

Imported from official source

Serial number: AV26-947Date: September 22, 2026 As of September 22, 2026, Arista Networks is affected by a vulnerability in the following product: VeloCloud Orchestrator (VCO) On-Prem Versions 5.2.0 to 5.2.3.15 Versions 6.1.0 to 6.1.3.7 Versions 6.4.0 to 6.4.2.7 Versions 7.0.0 to 7.0.0.2 Update 1 On September 22, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-93952 to their Known Exploited Vulnerabilities (KEV) Database. Open-source reporting indicates that CVE-2026-93952 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Advisory 0183 Arista Networks Advisories & Notices CISA KEV: CVE-2026-93952

This version

Version
2 of 2
Recorded
September 22, 2026 20:13
Change
Imported change
Content hash
f41458cf3d0c048860ae38ca5f236842
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.