Vulnerabilidad · Publicado 22/09/2026
VeloCloud Orchestrator (VCO) on-prem contiene una vulnerabilidad crítica (CVSS 10.0) que permite a atacantes remotos acceder a funcionalidades internas privilegiadas y comprometer la integridad del orquestador. La explotación exitosa impacta confidencialidad, integridad y disponibilidad de datos gestionados. Versiones hosted y dedicadas fueron afectadas, con implicaciones directas para proveedores de conectividad SD-WAN en México y LATAM que dependen de VCO para operaciones críticas.
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.
Score: 10/10 — Severidad: CRITICAL — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-20
Publicado en NIST NVD.