SECURITY·중요도 9·2026. 09. 22.·The Hacker News
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
── KO ──────────────────
VeloCloud Orchestrator의 새로운 취약점이 외부 공격에 노출되고 있습니다.
Arista에 따르면 2023년 9월 22일, VeloCloud Orchestrator(VCO)에 새로운 취약점이 발견되어 공격자들이 이를 악용하고 있습니다. 이 CVE-2026-93952는 원격 공격자가 로그인 접근 없이 내부 기능을 승인할 수 있게 하여 VCO 호스트에 영향을 미칠 수 있습니다. 특히, 인증된 Edge가 있는 설정에서 문제가 발생할 수 있습니다.
── EN ──────────────────
A new vulnerability in VeloCloud Orchestrator is being exploited by attackers.
According to Arista, a new flaw in the VeloCloud Orchestrator (VCO) was identified on September 22, 2023, leading to active exploitation by attackers. Tracked as CVE-2026-93952, this vulnerability allows a remote attacker to privilege internal functions without login access, potentially affecting the VCO host. This issue specifically impacts orchestrators configured to authenticate their Edges with certificates.