The only customers exposed are the ones who followed the hardening advice.
CVE-2026-93952 is a CVSS 10.0 improper input validation flaw in on-premises Arista VeloCloud Orchestrator. Arista disclosed it on 22 September 2026, having found it already in use…
Read the brief