VeloCloud Orchestrator Remote Access Vulnerability

Reported 23 Sep 2026 by otx · Severity: medium

VeloCloud Orchestrator (VCO) on-premises deployments contain a critical vulnerability allowing remote attackers to access privileged internal functionality and compromise the VCO host. The flaw, tracked as CVE-2026-93952 with a CVSS score of 10.0, enables attackers with network a