{
  "id": 10175296,
  "title": "Mapping VeloCloud Orchestrator Exposure: What ZoomEye Data Says About CVE-2026-93952",
  "url": "https://urgent.news/2026/09/27/mapping-velocloud-orchestrator-exposure-what-zoomeye-data-says-about",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-27T08:20:15.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/bianliang/mapping-velocloud-orchestrator-exposure-what-zoomeye-data-says-about-cve-2026-93952-pa7"
  },
  "original_language": "en",
  "account": null,
  "summary": "The CVE-2026-93952 vulnerability in VeloCloud Orchestrator (VCO) is actively being exploited, with Internet-wide scanning data indicating a potential exposure of a significant portion of the internet. ZoomEye's data shows that 6,050 internet-reachable systems have HTTP body content containing the VeloCloud string, indicating exposure. However, it is important to note that this figure does not confirm the vulnerability status of the systems. The data suggests that VCO systems should be behind strict access controls, as they are currently reachable from the public internet. Remediation steps include upgrading to a fixed build, restricting web interface access, and reviewing system logs for potential backdoor activity.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}