CVE-2026-93952
VeloCloud Orchestrator On-Prem Improper Input Validation Allows Remote Access to Privileged Functionality (CVE-2026-93952)
CVE-2026-93952 is a critical improper input validation issue in on-premises VeloCloud Orchestrator. CISA KEV lists it as actively exploited. Fixed builds listed are 5.2.3.16 and 6.4.2.8; apply the relevant build or restrict network exposure.
What happened
CVE-2026-93952 is a critical improper input validation issue in VeloCloud Orchestrator (VCO) on-prem. An attacker can reach the orchestrator over the network, without credentials and without any user action, and access privileged internal functionality on the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and of data managed by the orchestrator.
The CVSS 4.0 score is 9.5. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 22 September 2026, with a due date of 25 September 2026; CISA SSVC rates exploitation as active. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.
Who is affected
On-premises VeloCloud Orchestrator versions 5.2.0 to 5.2.3.15, 6.1.0 to 6.1.3.7, 6.4.0 to 6.4.2.7, and 7.0.0 to 7.0.0.2 are affected. The orchestrator is central management infrastructure for VeloCloud deployments and the data they rely on, so compromise can have wide impact. Hosted and Dedicated versions were impacted and have already been patched.
What to do now
- Apply the vendor's fixed build where it matches your affected version: velocloud_orchestrator 5.2.3.16 or 6.4.2.8.
- No fixed build is listed for affected versions 6.1.0 to 6.1.3.7 or 7.0.0 to 7.0.0.2. Treat those versions as vulnerable, isolate the orchestrator from untrusted networks, and follow vendor instructions before reintroducing it.
- Review any internet-exposed VCO and restrict access to authorised management networks only.
- CISA KEV set a due date of 25 September 2026. Confirm patch status and monitor for unexpected privileged activity.
How to detect it
The advisory does not list specific indicators of compromise. Because exploitation involves remote access to privileged internal functionality, consider monitoring the VCO host for unexpected administrative sessions, configuration changes, or new privileged accounts, especially from unexpected source networks.
Beyond the patch
Patch first, but also treat this as a reason to reduce how much of your network is reachable before the next advisory. Our Virtual CISO Services (vCISO) help identify and close the kind of unauthenticated network exposure this vulnerability exploits. Where CISA KEV says exploitation is active, Managed Detection & Response (MDR) provides the detection and response capacity to catch post-exploitation activity on the orchestrator before it becomes a wider incident.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| VeloCloud Orchestrator (VCO) On-Prem | 5.2.0 – ≤ 5.2.3.15 6.1.0 – ≤ 6.1.3.7 6.4.0 – ≤ 6.4.2.7 7.0.0 – ≤ 7.0.0.2 | No fixed version listed yet |