:

ARISTA PATCHES ACTIVELY EXPLOITED VELOCLOUD ZERO-DAY

SECURITY DESK■ 1 MIN READ
THU, SEP 24, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Arista Networks has released security patches for a zero-day vulnerability in VeloCloud Orchestrator (VCO) On-Prem that is currently being exploited in the wild.

The vulnerability affects VeloCloud Orchestrator on-premises deployments. Arista did not disclose specific technical details about the flaw or the nature of active exploitation, but confirmed patches are available. VeloCloud Orchestrator is a centralized management platform used by enterprises to control and monitor SD-WAN deployments across distributed networks. On-premises versions are particularly common in large organizations managing sensitive infrastructure. Organizations running VCO On-Prem should prioritize applying the available patches immediately given active exploitation. Arista recommends checking their security advisories for specific version updates and deployment guidance. The patch release underscores ongoing security challenges in network infrastructure software as attackers increasingly target management platforms that control critical enterprise connectivity.

■ SOURCES

► Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A Florida woman spent 13 days in jail after license plate reader data from Flock Security incorrectly linked her vehicle to a fatal hit-and-run. The misidentification highlights growing concerns about the accuracy and use of automated surveillance technology in criminal investigations.

JUST NOW— AI Desk

A $357 million hack of crypto exchange Bitget on Thursday is attributed to North Korean hackers, pushing the nation-state's digital-asset thefts past $1 billion this year, according to analytics firm Elliptic Enterprises.

6H AGO— Security Desk

A U.S. Army soldier was sentenced to 70 months in federal prison for hacking AT&T and Verizon and stealing call and text metadata from over 100 million customers. He was also ordered to pay nearly $300,000 in restitution.

7H AGO— Industry Desk

A cross-site request forgery (CSRF) vulnerability in the popular Elementor WordPress plugin could allow unauthenticated attackers to create administrator accounts on affected sites.

10H AGO— Industry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.