Back

CRITICAL KEV

Security Advisory 0183

Published Sep 22, 2026 ·Due Sep 25, 2026

Description

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

Affected products

Remediation

Vendor solution

The recommended resolution is to upgrade to a remediated VCO software version at your earliest convenience. These vulnerabilities have been fixed in the following releases: - VCO 5.2.3.16 and later in the 5.2.3 train - VCO 6.4.2.8 and later in the 6.4.2 train

Releases in other release trains that fix this will be added over time. For VCOs not on a supported release train, customers can contact TAC to discuss possible upgrade options.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Arista
Published Sep 22, 2026
Updated Sep 23, 2026
Reserved Sep 19, 2026
CISA Vulnrichment
Updated Sep 22, 2026
NVD
Status Analyzed
Modified Sep 23, 2026
Red Hat
Severity n/a
Public date n/a