Summary
Arista Networks has released an emergency patch for CVE-2026-52174, a near-maximum-severity zero-day vulnerability in VeloCloud Orchestrator, the cloud-based management platform for Arista’s VeloCloud SD-WAN product line. The vulnerability is rated CVSS 9.9 and allows an unauthenticated remote attacker to achieve arbitrary code execution on the VeloCloud Orchestrator server. VeloCloud Orchestrator is the centralized control plane for SD-WAN deployments, managing network topology, routing policy, security policy, and device configuration across all connected branch and data center edge devices. Successful exploitation gives an attacker complete visibility into and control over the entire SD-WAN network managed by the compromised orchestrator. CISA has added CVE-2026-52174 to its Known Exploited Vulnerabilities catalog with a September 25, 2026 remediation deadline.
Timeline
| Date | Event |
|---|---|
| Prior to Sep 22, 2026 | CVE-2026-52174 exploited as zero-day in attacks; Arista threat intelligence and third-party researchers identify active exploitation |
| Sep 22, 2026 | Arista releases emergency patch for VeloCloud Orchestrator; discloses CVE-2026-52174 and confirms active exploitation |
| Sep 22-23, 2026 | CISA adds CVE-2026-52174 to KEV catalog; sets September 25 federal remediation deadline |
What Happened
CVE-2026-52174 is an unauthenticated remote code execution vulnerability in VeloCloud Orchestrator’s API handling layer. The orchestrator’s REST API accepts unauthenticated requests on certain endpoints for device onboarding and health reporting. A specially crafted API request can trigger a memory corruption condition that allows an attacker to execute arbitrary commands on the orchestrator server with administrative access to the orchestrator’s database and management functions.
The security consequence of orchestrator-level compromise extends across the entire SD-WAN fabric. VeloCloud Orchestrator holds the complete configuration and topology of all connected SD-WAN edges. An attacker with orchestrator access can read all network traffic routing tables and policies, modify firewall and routing rules across the entire SD-WAN fabric, redirect traffic through attacker-controlled paths, push malicious configuration updates to any connected edge device, and extract all network credentials and authentication material stored in the orchestrator database. Organizations operating VeloCloud SD-WAN should treat the orchestrator as compromised if it was running a vulnerable version while internet-accessible and initiate incident response alongside patching.
Domain Intelligence
arista.com — 61.2
arista.com scores in the low-trust range at 61.2. Arista Networks is the vendor of the affected VeloCloud Orchestrator product and the party that patched CVE-2026-52174 and published remediation guidance.
The Trust Observatory · thetrustobservatory.com · September 23, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026