
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities (KEV) catalog.
Below are the flaws added to the KeV catalog:
- CVE-2025-68686 (CVSS score of 5.3) Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
- CVE-2026-16812 (CVSS score of 10.0) Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
CVE-2025-68686 is an information disclosure vulnerability affecting multiple versions of Fortinet FortiOS. The flaw allows a remote, unauthenticated attacker to bypass a security patch designed to prevent the persistence of malicious symbolic links that attackers may leave behind after compromising a device.
The vulnerability cannot be exploited on its own. An attacker must first gain filesystem-level access to the FortiOS appliance by exploiting a separate vulnerability. Once the system has already been compromised, specially crafted HTTP requests can be used to bypass the symbolic link protection introduced by Fortinet, potentially exposing sensitive information that should no longer be accessible. In essence, the flaw weakens the effectiveness of the earlier mitigation, allowing attackers who have already established a foothold on the device to continue accessing protected resources or maintain aspects of their post-exploitation activity.
The vulnerability CVE-2026-16812 affects the on-premises VMware VeloCloud Orchestrator (VCO) and exposes privileged internal functionality that was intended to be accessible only by trusted internal components. Due to this flaw, a remote attacker can invoke these internal functions, potentially gaining unauthorized access to the underlying VCO host.
Successful exploitation could compromise the confidentiality, integrity, and availability of both the orchestrator and the network data it manages, enabling attackers to access sensitive information, modify configurations, or disrupt SD-WAN management operations. VMware has confirmed that the flaw is actively exploited in the wild. The Hosted and Dedicated VCO offerings were patched before public disclosure, while organizations running on-premises deployments should apply the available security updates as soon as possible.
Arista said the vulnerability was discovered externally and is being actively exploited, but did not disclose when it was reported or how many customers may have been affected. The company also published three IP addresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to block them and check logs for signs of compromise.
“If compromise is suspected, operators should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible.” reads the company’s advisory.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the Arista VeloCloud Orchestrator flaw by July 20, 2026, and the Fortinet FortiOS flaw by August 10, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)



