[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ffxGmk4AyCL-1SiYG-vZjoXj9dLYOl_p5khYYvmD4238":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":43},"47b2f6a8-fcd8-414b-91cf-d38552991ea3","actively-exploited-arista-vco-zero-day-demands-immediate-patching","9841b80d-405e-4af2-9599-cfe16c2dbf9c","Actively Exploited Arista VCO Zero-Day Demands Immediate Patching","A critical zero-day vulnerability (CVE-2026-93952) in Arista's on-premises VeloCloud Orchestrator was actively exploited before patches were available, highlighting the danger of internet-facing network orchestration platforms running unvalidated input handling. The improper input validation flaw allows unauthenticated remote attackers to reach privileged internal functionality, threatening the confidentiality, integrity, and availability of affected environments. Its addition to CISA's Known Exploited Vulnerabilities (KEV) catalog underscores the real-world threat and triggers mandatory remediation timelines for federal agencies. Organizations that lack mature patch prioritization processes or accurate asset inventories are especially at risk of delayed response when zero-days like this emerge. The incident reinforces that critical network management infrastructure must be treated as a high-priority attack surface requiring continuous vulnerability monitoring.","**Immediate actions:**\n- Apply Arista's emergency patches for CVE-2026-93952 to all on-premises VeloCloud Orchestrator deployments without delay.\n- Restrict external network access to VCO management interfaces using firewall rules or access control lists until patching is confirmed complete.\n- Check threat intelligence feeds and CISA's KEV catalog to determine whether your environment shows indicators of prior compromise.\n\n**Long-term improvements:**\n- Establish a formal emergency patching procedure with defined SLAs (e.g., 24–72 hours) for critical\u002Factively exploited vulnerabilities.\n- Maintain a continuously updated, authoritative inventory of all network appliances and orchestration platforms, including version and patch status.\n- Implement network segmentation to isolate management and orchestration planes from general user and internet-facing traffic.\n\n**Detection measures:**\n- Deploy continuous vulnerability scanning targeted at internet-facing and management-tier assets to detect unpatched systems in near real-time.\n- Enable detailed logging and behavioral monitoring on network orchestration platforms to detect anomalous access to privileged functionality.\n- Subscribe to CISA KEV catalog alerts and vendor security advisories to ensure zero-day notifications trigger an immediate response workflow.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","CIS Control 4: Secure Configuration of Enterprise Assets","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management","NIST SI-2: Flaw Remediation","NIST RA-5: Vulnerability Monitoring and Scanning","NIST SC-7: Boundary Protection","CISA Known Exploited Vulnerabilities (KEV) Catalog","CISA BOD 22-01: Reducing Significant Risk of Known Exploited Vulnerabilities","ITIL Change Management: Emergency Change Process","ISO\u002FIEC 27001:2022 – A.8.8: Management of Technical Vulnerabilities","published","2026-09-23T10:21:47.159683+00:00","2026-09-23T10:21:47.062+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.securityweek.com\u002Farista-urges-immediate-patching-of-exploited-vco-zero-day\u002F","arista-urges-immediate-patching-of-exploited-vco-zero-day-92c512","Arista Urges Immediate Patching of Exploited VCO Zero-Day",[31,37],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[44],{"id":45,"date":46,"edition":47,"title":48,"audio_url":49},"9afea3bd-f321-49a8-b827-3e00ffa57a8a","2026-09-23","afternoon","ThreatNoir Afternoon Brief — September 23","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-23\u002Fthreatnoir-afternoon-brief-2026-09-23.mp3"]