{"id":1940,"date":"2026-09-24T12:02:16","date_gmt":"2026-09-24T06:32:16","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1940"},"modified":"2026-09-24T17:26:07","modified_gmt":"2026-09-24T11:56:07","slug":"velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/","title":{"rendered":"VeloCloud Orchestrator Zero-Day Puts SD-WAN Control Planes at Risk"},"content":{"rendered":"<p>The VeloCloud Orchestrator exploit puts SD-WAN management infrastructure under immediate pressure. Arista disclosed <a href=\"https:\/\/thehackernews.com\/2026\/09\/new-cvss-100-velocloud-orchestrator.html?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=velocloud_orchestrator_exploit\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026-93952<\/a> on September 22, 2026, confirming active exploitation. The vulnerability carries a CVSS v3.1 score of 10.0; its CVSS v4.0 score is 9.5. Arista\u2019s advisory describes the exposure.<\/p>\n<p>For security administrators and network teams, the concern extends beyond one server. A compromised orchestrator can affect the data and devices under its control. The immediate task is to establish exposure, reduce access, and investigate suspicious activity.<\/p>\n<h2>How the VeloCloud Orchestrator exploit exposes management infrastructure<\/h2>\n<p>Arista classifies CVE-2026-93952 as improper input validation (CWE-20). Exploitation requires a vulnerable VCO release, certificate-based Edge authentication, network access to the VCO web interface, and an Edge authentication certificate\u2019s public portion. Tenant or operator credentials are unnecessary. Successful exploitation can expose privileged internal functionality and affect the host. Arista identifies the x-vc-opt header in nginx logs as an investigation indicator. Hosted and Dedicated deployments were also affected but have already been patched.<\/p>\n<p>This distinction matters when prioritizing remediation. Build an inventory that records each orchestrator\u2019s deployment model, software build, authentication configuration, and reachable management interfaces. Assign an owner to every exposed instance so network and security teams work from the same remediation list.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit.webp?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity-kit\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity-kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            Download the Resource Kit\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h3>Validate exposure to the VeloCloud Orchestrator exploit<\/h3>\n<p>Arista\u2019s advisory lists these affected builds and fixes as checked on September 24, 2026:<\/p>\n<table>\n<thead>\n<tr>\n<th>Release train<\/th>\n<th>Affected versions<\/th>\n<th>Fixed release listed<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>5.2<\/td>\n<td>5.2.3.15 and earlier within the train<\/td>\n<td>5.2.3.16<\/td>\n<\/tr>\n<tr>\n<td>6.1<\/td>\n<td>6.1.3.7 and earlier within the train<\/td>\n<td>None listed<\/td>\n<\/tr>\n<tr>\n<td>6.4<\/td>\n<td>6.4.2.7 and earlier within the train<\/td>\n<td>6.4.2.8<\/td>\n<\/tr>\n<tr>\n<td>7.0<\/td>\n<td>7.0.0.2 and earlier within the train<\/td>\n<td>None listed<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Mitigation for release trains 6.1 and 7.0: As of September 24, 2026, Arista lists no fixed releases for these trains. Restrict VCO web-interface access to trusted administrative networks while awaiting patches. Review outbound traffic and administrator activity, and monitor for web shells or backdoor daemons.<\/p>\n<h3>Investigate compromise alongside patching<\/h3>\n<p>Arista identifies <code>\/usr\/local\/sbin\/.vcnode.js<\/code>, <code>\/usr\/local\/sbin\/vc-sysmond<\/code>, <code>\/etc\/systemd\/system\/vc-sysmon.service<\/code>, and the nginx header <code>x-vc-opt<\/code> as investigation leads. Preserve evidence and contact TAC if indicators appear.<\/p>\n<p>Use a coordinated response workflow:<\/p>\n<ul>\n<li><strong>Reduce exposure:<\/strong> Limit management access to trusted administrative networks and review unnecessary outbound connectivity.<\/li>\n<li><strong>Examine activity:<\/strong> Check unexpected outbound traffic, administrator changes, web shells, and backdoor daemons.<\/li>\n<li><strong>Establish context:<\/strong> Compare suspicious timestamps with approved maintenance records and administrator sessions.<\/li>\n<li><strong>Track recovery:<\/strong> Record investigation findings, upgrade completion, unresolved questions, and the person responsible for each follow-up.<\/li>\n<\/ul>\n<p>Treat missing indicators cautiously. A search result should inform the investigation, while closure should require documented evidence that the team has addressed both exposure and suspected compromise.<\/p>\n<p>Keep an incident timeline shared between network operators and responders. Record who changed access rules, when updates completed, and which observations remain unexplained. Map each orchestrator to its managed sites so the team can prioritize validation and communicate potential service impact to affected business owners.<\/p>\n<h2>How Hexnode supports endpoint security around VCO<\/h2>\n<p>The Hexnode UEM and Hexnode XDR capabilities below apply to supported Windows and macOS administrative workstations used to manage VCO. They do not describe deployment on the Linux-based VCO host itself. Follow Arista\u2019s guidance for orchestrator investigation, software upgrades, and recovery.<\/p>\n<table>\n<thead>\n<tr>\n<th>Security objective<\/th>\n<th>Hexnode capability for Windows and macOS administrative workstations<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Identify endpoint compliance gaps<\/td>\n<td><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> Compliance Policies evaluate configured criteria, including OS Version, BitLocker, and FileVault. Apply appropriate requirements to administrative device groups.<\/td>\n<\/tr>\n<tr>\n<td>Govern application access<\/td>\n<td>A supported identity-provider integration can use Hexnode UEM compliance signals in Conditional Access decisions for applications covered by that integration.<\/td>\n<\/tr>\n<tr>\n<td>Contain compromised endpoints<\/td>\n<td><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> supports one-click device isolation, process termination, process tree termination, and file quarantine. Administrators can quarantine malicious binaries discovered during an endpoint compromise. Device isolation preserves the endpoint\u2019s connection to the Hexnode XDR console for continued investigation.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Validate application integration before promising device-based access enforcement for a particular administrative portal. An application sign-in policy does not establish protection for every exposed VCO service endpoint. Likewise, endpoint response actions should follow investigation of the affected workstation; they do not establish that the orchestrator itself is clean.<\/p>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why is CVE-2026-93952 considered critical for VeloCloud Orchestrator deployments?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>CVE-2026-93952 can allow an unauthenticated attacker to reach privileged internal functionality and affect the VCO host when the required exploitation conditions are present. A compromised orchestrator can also put the data and managed devices under its control at risk.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Which VeloCloud Orchestrator configurations are exposed to CVE-2026-93952?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Exploitation requires a vulnerable VCO release configured for certificate-based Edge authentication, access to the VCO web interface, and the public portion of an Edge authentication certificate. Tenant or operator credentials are not required under these conditions.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Make recovery an operational requirement<\/h3>\n<p>Treat SD-WAN management infrastructure as a critical administrative asset. Prioritize exposed instances, apply available fixes, and coordinate investigation across network and security teams. Set explicit closure criteria: verified software, reviewed access, documented findings, and accountable owners for remaining actions. Strong endpoint controls support that process, while the orchestrator requires its own remediation and recovery decisions.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen Endpoint Threat Response<\/h5><p>Secure administrator endpoints, detect suspicious activity, and accelerate threat response with Hexnode UEM and XDR.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The VeloCloud Orchestrator exploit puts SD-WAN management infrastructure under immediate pressure. Arista disclosed CVE-2026-93952 on&#8230;<\/p>\n","protected":false},"author":6,"featured_media":1972,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[12,20],"class_list":["post-1940","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zero-day","category-network-and-vpn","product_category-extended-detection-and-response","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>VeloCloud Orchestrator Exploit: CVE-2026-93952<\/title>\n<meta name=\"description\" content=\"The VeloCloud Orchestrator exploit targets certificate-based deployments. Learn which versions are affected and how to respond.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"VeloCloud Orchestrator Exploit: CVE-2026-93952\" \/>\n<meta property=\"og:description\" content=\"The VeloCloud Orchestrator exploit targets certificate-based deployments. Learn which versions are affected and how to respond.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-24T06:32:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-24T11:56:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/VeloCloud-Orchestrator-Zero-Day-Puts-SD-WAN-Control-Planes-at-Risk.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"VeloCloud Orchestrator Zero-Day Puts SD-WAN Control Planes at Risk\",\"datePublished\":\"2026-09-24T06:32:16+00:00\",\"dateModified\":\"2026-09-24T11:56:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\\\/\"},\"wordCount\":838,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/VeloCloud-Orchestrator-Zero-Day-Puts-SD-WAN-Control-Planes-at-Risk.png?format=webp\",\"articleSection\":[\"Zero-Day\",\"Network and VPN\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\\\/\",\"name\":\"VeloCloud Orchestrator Exploit: CVE-2026-93952\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/VeloCloud-Orchestrator-Zero-Day-Puts-SD-WAN-Control-Planes-at-Risk.png?format=webp\",\"datePublished\":\"2026-09-24T06:32:16+00:00\",\"dateModified\":\"2026-09-24T11:56:07+00:00\",\"description\":\"The VeloCloud Orchestrator exploit targets certificate-based deployments. Learn which versions are affected and how to respond.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/VeloCloud-Orchestrator-Zero-Day-Puts-SD-WAN-Control-Planes-at-Risk.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/VeloCloud-Orchestrator-Zero-Day-Puts-SD-WAN-Control-Planes-at-Risk.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"VeloCloud Orchestrator Zero-Day Puts SD-WAN Control Planes at Risk\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"VeloCloud Orchestrator Zero-Day Puts SD-WAN Control Planes at Risk\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"description\":\"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"VeloCloud Orchestrator Exploit: CVE-2026-93952","description":"The VeloCloud Orchestrator exploit targets certificate-based deployments. Learn which versions are affected and how to respond.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/","og_locale":"en_US","og_type":"article","og_title":"VeloCloud Orchestrator Exploit: CVE-2026-93952","og_description":"The VeloCloud Orchestrator exploit targets certificate-based deployments. Learn which versions are affected and how to respond.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-24T06:32:16+00:00","article_modified_time":"2026-09-24T11:56:07+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/VeloCloud-Orchestrator-Zero-Day-Puts-SD-WAN-Control-Planes-at-Risk.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"VeloCloud Orchestrator Zero-Day Puts SD-WAN Control Planes at Risk","datePublished":"2026-09-24T06:32:16+00:00","dateModified":"2026-09-24T11:56:07+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/"},"wordCount":838,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/VeloCloud-Orchestrator-Zero-Day-Puts-SD-WAN-Control-Planes-at-Risk.png?format=webp","articleSection":["Zero-Day","Network and VPN"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/","url":"https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/","name":"VeloCloud Orchestrator Exploit: CVE-2026-93952","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/VeloCloud-Orchestrator-Zero-Day-Puts-SD-WAN-Control-Planes-at-Risk.png?format=webp","datePublished":"2026-09-24T06:32:16+00:00","dateModified":"2026-09-24T11:56:07+00:00","description":"The VeloCloud Orchestrator exploit targets certificate-based deployments. Learn which versions are affected and how to respond.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/VeloCloud-Orchestrator-Zero-Day-Puts-SD-WAN-Control-Planes-at-Risk.png?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/VeloCloud-Orchestrator-Zero-Day-Puts-SD-WAN-Control-Planes-at-Risk.png?format=webp","width":1340,"height":700,"caption":"VeloCloud Orchestrator Zero-Day Puts SD-WAN Control Planes at Risk"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/velocloud-orchestrator-zero-day-puts-sd-wan-control-planes-at-risk\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"VeloCloud Orchestrator Zero-Day Puts SD-WAN Control Planes at Risk"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"description":"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1940","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1940"}],"version-history":[{"count":5,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1940\/revisions"}],"predecessor-version":[{"id":1956,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1940\/revisions\/1956"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1972"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1940"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1940"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}