CISA added CVE-2026-93952 (Arista VeloCloud Orchestrator) to its Known Exploited Vulnerabilities catalog on September 22, 2026, which means there is reliable evidence of exploitation in the wild. Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation…
Why it matters
CISA lists this as exploited in the wild. Unpatched VeloCloud Orchestrator systems are exposed to active attacks now.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.
CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing…
Why it matters
CISA lists this as exploited in the wild. Unpatched BIG-IP and Multiple Products systems are exposed to active attacks now.