Illustrative image generated with AI
CISA Raises Alarm on Two New Actively Exploited Vulnerabilities in FortiOS and Arista VeloCloud
CISA added two new actively exploited vulnerabilities affecting FortiOS and Arista VeloCloud Orchestrator to its KEV catalog. Read impact and mitigations.
Text generated by artificial intelligence, published without human review. AI transparency
Introduction
On July 27, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) catalog with two new security flaws, for which active malicious activity has already been detected. The vulnerabilities, identified as CVE-2025-68686 and CVE-2026-16812, affect Fortinet FortiOS systems and the on-premises Arista VeloCloud Orchestrator, respectively. This action falls under the Binding Operational Directive BOD 26-04, which mandates U.S. federal agencies to prioritize remediation of vulnerabilities listed in the catalog, especially those that provide full post-exploitation control.
Technical Analysis
The two CVEs differ in type but share the criticality of active in-the-wild exploitation.
CVE-2025-68686 (Fortinet FortiOS): this is a sensitive information disclosure. An unauthorized actor can exploit the flaw to access critical appliance data, bypassing confidentiality mechanisms. The nature of the vulnerability suggests a network vector that does not require prior credentials, but exact technical details are provided in the official Fortinet advisory.
CVE-2026-16812 (Arista VeloCloud Orchestrator On-Prem): this is a classic operating system-level command injection. Insufficient input sanitization allows an attacker to inject arbitrary commands, potentially obtaining a shell with application privileges and escalating to full compromise of the orchestration platform.
According to the CISA bulletin, both vulnerabilities are already exploited in real-world attacks, significantly raising their severity, despite the lack of official CVSS scores at the time of publication.
Impact
The impact is twofold and severe. For FortiOS, the loss of sensitive information can facilitate further targeted attacks or mapping of the network infrastructure. In the case of Arista VeloCloud Orchestrator, the command injection paves the way for arbitrary command execution and thus the full compromise of the system managing the entire SD-WAN, jeopardizing the connectivity and traffic of all connected sites. Both products are widely used in enterprise and government environments, making the observed malicious activity particularly concerning.
Mitigation
CISA requires Federal Civilian Executive Branch (FCEB) agencies to apply vendor-provided patches by the specified deadlines and recommends all organizations adopt an immediate risk-based approach. Recommended measures include:
- Immediately verify the version of FortiOS and Arista VeloCloud Orchestrator in use.
- Apply official patches released by Fortinet and Arista respectively, consulting the dedicated security advisories.
- If patches are unavailable, consider isolating exposed devices or implementing restrictive network controls.
- Monitor logs and traffic to detect any exploitation attempts, leveraging indicators of compromise shared by vendors or CISA itself.
FAQ
1. What is the Known Exploited Vulnerabilities (KEV) catalog? The KEV catalog is a public list managed by CISA that compiles vulnerabilities for which there is evidence of active exploitation in real-world attacks. Its purpose is to provide a prioritized reference for remediation, especially for U.S. government agencies subject to regulatory obligations like BOD 26-04.
2. CVE-2025-68686 has 2025 in its identifier: does that mean it was known for some time? The year in the CVE identifier is part of the name and does not always reflect the year of discovery or fix; it may indicate the year the code was initially assigned. In this case, CISA has not provided details on the vulnerability’s history, but inclusion in the KEV only occurs after the detection of active exploits, regardless of the flaw’s age.
3. What should an organization using VeloCloud do if it hasn’t received vendor notifications yet? The CISA bulletin confirms that vendors have made mitigation guidance available. Therefore, it is necessary to immediately contact Arista support, verify the orchestrator version, and apply patches following official procedures. In the meantime, it is advisable to limit network exposure by restricting administrative access to trusted networks only and enabling detailed logging.
Sources
This article is an original reworking based on the sources below.
- The Hacker News
- SecurityWeek
- Security Affairs
- CISA Advisories
CVEs covered in this article
- CVE-2026-16812Critical10.0VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by
- CVE-2025-68686Medium5.9An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass
