TGViewer
Netlas.io Netlas.io @netlas · 2.31K subscribers
Post #637 130
CVE-2026-93952: Improper Input Validation in VeloCloud Orchestrator, 10.0 Rating 🔥

A recently disclosed improper input validation vulnerability in on-premises VeloCloud Orchestrator (VCO) allows a remote attacker to access privileged internal functionality and impact the VCO host. This vulnerability is known to be actively exploited in the wild!

Search at Netlas.io:
👉 Link: https://nt.ls/Z9gGT
👉 Dork: http.body:"single-spa-application:@velocloud/vco-header" OR http.body:"vco/branding.css" OR http.body:"vco/favicon"

Vendor's advisory:
https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
  • 🔥 3
  • ❤ 1
More from @netlas
  1. Sep 21, 2026CVE-2026-13684 and others: Multiple vulnerabilities in Synology DSM, up to 9.8 Rating 🔥 S…
  2. Sep 18, 202611 new vulnerabilities in WordPress, no CVE assigned yet ❗️ WordPress 7.1.1 security relea…
  3. Sep 17, 2026CVE-2026-20329 and others: Multiple vulnerabilities in Cisco ASA, up to 9.9 Rating 🔥 Cisc…
  4. Sep 16, 2026CVE-2026-61642: Request smuggling is possible in Squid proxy, 7.7 Rating 🔥 A recently dis…
  5. Sep 15, 2026CVE-2026-78006 & CVE-2026-78159: Two unauthenticated vulnerability chains leading to RCE i…
  6. Sep 11, 2026🔌 Plug & Pwn: Mapping the Windows PnP Auto-Install Attack Surface Windows Plug & Play can…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →