Arista Networks and F5 have released security updates for two critical zero-day vulnerabilities that are being actively exploited by attackers.
Arista Networks patched CVE-2026-93952, a high-severity flaw affecting VeloCloud Orchestrator (VCO) On-Prem deployments. The vulnerability can allow remote attackers to access privileged internal VCO functions without authentication or user interaction.
The flaw affects VCO deployments using certificate-based authentication between VeloCloud Edge and VCO. Arista said attackers need network access to the VCO web interface and access to the public portion of the VeloCloud Edge authentication certificate.
The vendor has already patched hosted VCO deployments running versions 5.2.3.16 and later, and 6.4.2.8 and later. Security updates are also planned for older 6.1.3.7-and-below and 7.0.0.2-and-below releases.
Separately, F5 released updates for CVE-2026-94127, a high-risk BIG-IP Access Policy Manager (APM) vulnerability being used in remote code execution attacks.
The flaw affects BIG-IP APM systems configured as an OAuth Authorization Server with an APM access policy and OAuth profile on a virtual server. F5 said systems using APM only as an OAuth Client or Resource Server are not affected.
F5 is also advising customers to check for signs of compromise, including repeated OAuth authentication failures followed by suspicious commands and a TMM SIGABRT.