Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Build the exercise around five decisions: whether your VeloCloud Orchestrator (VCO) deployment is affected and exposed, how to restrict access without destroying evidence, whether to upgrade or contact Arista TAC, how to assess possible compromise, and what must be validated before recovery is complete. Arista says CVE-2026-93952 is actively exploited and that successful exploitation may affect VCO and its managed data. This scenario is for response planning, not a substitute for the live vendor advisory.
What the exercise is testing
CVE-2026-93952 concerns VeloCloud Orchestrator On-Prem. Arista Networks Security Advisory 0183, dated September 22, 2026 and revised September 23, identifies the issue as actively exploited. The advisory assigns CVSS 3.1 Base Score 10.0 and CVSS 4.0 Base Score 9.5. Those severity scores describe the vulnerability; they do not establish that a particular organization’s VCO is exposed or compromised.
The exercise should test whether the team can establish applicability, make a defensible containment decision, preserve and correlate evidence, choose a supported remediation path, and validate the orchestrator and managed Edge devices during recovery. Keep the scenario in a simulated environment; do not attempt exploitation on production systems.
Establish whether the deployment is in scope
Check deployment type and software version
Arista identifies VCO On-Prem as affected. The advisory says hosted VCO, including Dedicated deployments, was also affected but had already been patched. Confirm deployment type and the exact installed version, then compare it with the vendor’s affected ranges:
#1 Best Overall
| Release train | Affected versions listed by Arista | Fixed version listed by Arista |
|---|---|---|
| 5.2.x | 5.2.3.15 and earlier | 5.2.3.16 and later in the 5.2.3 train |
| 6.1.x | 6.1.3.7 and earlier | |
| 6.4.x | 6.4.2.7 and earlier | 6.4.2.8 and later in the 6.4.2 train |
| 7.0.x | 7.0.0.2 and earlier |
These are the ranges and fixes in the advisory revision dated September 23, 2026; verify the current advisory before acting because Arista says fixes for other trains will be added over time. Arista also states that an unlisted software release is not vulnerable, regardless of hardware platform. Do not infer that a release is fixed merely because it is newer than an affected version; use the vendor’s stated train-specific guidance.
Check the exposure prerequisites
Arista says exposure depends on all three of these conditions:
- Certificate-based Edge-to-VCO authentication is configured.
- The public portion of the Edge authentication certificate is available.
- The VCO web interface is network-accessible.
Tenant or operator credentials are not required for exploitation. Limiting the web interface to trusted administrative networks reduces exposure risk. In the exercise, have the network and platform owners explain how they would verify each prerequisite rather than treating an alert or a version match as proof of compromise.
Rank #2
Set the exercise roles and decision authority
Include the people who can investigate the control plane and authorize service-impacting changes. Assign a facilitator to deliver injects and record decisions, and name one person to maintain the event timeline.
- SD-WAN/network operator: establishes deployment, version, exposure, connectivity, and managed Edge context.
- Security operations: leads log review, indicator validation, and evidence correlation.
- Incident commander: coordinates decisions, priorities, and handoffs.
- Identity or credential owner: plans credential review and rotation if compromise is suspected.
- Infrastructure/platform operator: handles host evidence, upgrade planning, and trusted restoration options.
- Service owner or communications lead: assesses operational impact and coordinates internal updates.
- Authorized decision-maker: can approve restrictions, upgrades, or other changes that may interrupt service.
Run the tabletop: injects and decisions
Read each inject to participants in sequence. Ask them to state what they know, what remains unconfirmed, what evidence they need, who owns the next action, and what decision threshold they are using. Record the time of each decision and any assumed facts.
1. An unusual VCO web alert arrives
A monitoring alert flags unusual requests to the VCO web interface. Ask the team to identify the deployment type and exact release, determine whether the listed exposure prerequisites apply, and decide who can restrict web access. The alert alone does not prove exploitation.
Rank #3
2. Request patterns look suspicious
Show sample observations such as URL-like path components, encoded characters, references to local or internal services, or a high request rate. Ask which VCO web access logs, backend application logs, system logs, and database records should be preserved; how timestamps will be aligned; and who authorizes containment. Arista recommends preserving relevant logs and filesystem timestamps before remediation where operationally feasible if compromise is suspected.
Free tools Windows power users keep installed
One-click scans. No signup required.
3. Host or administrator activity raises concern
Introduce unexpected outbound HTTP/S from the VCO, an administrator change with no change ticket, or an unexpected privileged maintenance action. Have responders correlate the web, backend application, system, and database evidence with endpoint and network observations. Ask whether they would preserve host state, contact TAC, and broaden the investigation to configuration, device inventory, credentials, certificates, key material, or database access.
4. An indicator lead appears
Provide one or more of these leads: a file or service named in the advisory, the x-vc-opt HTTP header in nginx logs, or traffic associated with one of the listed IP addresses. Ask participants to check context, timestamps, and corroborating evidence before classifying a match. Arista explicitly says there is no single definitive indicator of compromise for this issue.
Rank #4
5. The installed train determines the remediation path
Reveal the exact installed version. If the deployment is on a train with a fixed version listed in the advisory, ask the team to plan and authorize an upgrade to the applicable fixed release. If its train has no fix listed in that advisory revision, or it is unsupported, ask what interim controls remain in place and who will contact Arista TAC about upgrade options. Teams should verify the live advisory rather than treating the September 23 list as current indefinitely.
6. Upgrade completes, but compromise remains possible
Tell participants the software has been upgraded, then ask what evidence is needed before they declare recovery. Require named owners and completion evidence for credential rotation where appropriate, administrator activity review, validation of managed Edge state, and restoration or replacement of affected orchestrator instances from trusted sources if compromise is suspected.
Evidence and interim controls to discuss
Correlate leads rather than relying on a single match
Arista’s investigation guidance includes unexpected VCO web activity; unusual outbound HTTP/S; unapproved configuration changes; unexpected privileged maintenance or command execution; file creation; database export or archive artifacts; and unusual access to VCO databases, configuration, device inventory, credentials, certificates, or key material. Correlate these leads across relevant logs and host or network observations. A single indicator is not a definitive finding.
Best Value
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
The advisory specifically names /usr/local/sbin/.vcnode.js, /usr/local/sbin/vc-sysmond, and /etc/systemd/system/vc-sysmon.service; the x-vc-opt HTTP header in nginx logs; IP addresses 142.93.149.77 and 104.248.126.159; and MD5 dc78e206eaeadec59fc5801fe4556bd0 for vc-sysmond. Treat these as vendor-listed investigation leads, not proof on their own. Preserve relevant VCO web access, backend application, system, and database logs and filesystem timestamps before remediation when feasible.
Decide which interim restrictions are practical
Until fixed software is deployed, Arista recommends restricting VCO web access to trusted administrative networks, monitoring for access from known malicious source IPs and unexpected outbound activity, considering blocks on outbound ports unnecessary for normal operations, monitoring for backdoor daemons and webshells, and reviewing recent administrator activity for unexpected changes. Ask teams to identify the owner and operational impact of each control, particularly any restriction that could affect service.
Evaluate the exercise
Score the response against observable decisions and evidence, not confidence or speed alone. The team should be able to:
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11- Identify the deployment type, exact release, affected range, and exposure prerequisites accurately.
- Restrict access to the VCO web interface through an authorized decision while preserving relevant evidence.
- Preserve logs, database records, and filesystem timestamps where feasible, and correlate events across systems.
- Distinguish an investigative lead from confirmed compromise.
- Use the train-specific fixed-version guidance correctly and account for trains without a listed fix.
- Assign owners for TAC contact, credential review or rotation, administrator review, Edge-state validation, and trusted restoration where needed.
- Define what evidence is required before service restoration and incident closure.
Source date and changing details
This scenario reflects Arista Networks Security Advisory 0183, published September 22, 2026 and revised September 23, 2026. A CVE record rendered by Threatint lists the CVE publication date and CISA KEV addition date as September 22, 2026, with a listed due date of September 25, 2026. Catalog status and deadlines can change; verify the current CISA record and Arista advisory before using those details for operational decisions.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

