Skip to content
Attacks on FortiOS and Arista VeloCloud observed

Attacks on FortiOS and Arista VeloCloud observed

Heise.De July 28, 2026

Fortinet's FortiOS and Arista's VeloCloud Orchestrator On-Prem have some highly critical security vulnerabilities that malicious actors are currently exploiting. The FortiOS vulnerability has been around for several months, while Arista admins can close the gap with an update since Monday this week.

The US cybersecurity authority CISA warns of the attacks and only names the vulnerability numbers targeted by attackers. The security vulnerability in FortiOS is in the SSL VPN and allows unauthorized reading of confidential information with manipulated HTTP requests – without prior authentication ( CVE-2025-68686 , CVSS 5.3 , risk “ medium ”). FortiOS versions 6.4, 7.0, 7.2, 7.4, and 7.6 are affected. Fortinet is only correcting this with versions 7.6.2 and 7.4.7 and newer. Those using older version branches must migrate to these. According to Fortinet, however, the vulnerability can only be exploited if an attacker has previously compromised the device at the file system level through another vulnerability. Fortinet's security advisory does not yet contain any information on currently observed exploits (the company states “No” for Known Exploited).

In a security advisory from Monday, Arista warns of a serious vulnerability in VeloCloud Orchestrator (VCO) On-Prem. Attackers from the network can access internal functions and influence the VCO host, which requires higher privileges ( CVE-2026-16812 , CVSS 10.0 , risk “ critical ”). These functions should not normally be externally accessible, Arista explains. The manufacturer has already provided patches for hosted and managed versions, but IT administrators with on-premises installations must act quickly themselves. The corrected VeloCloud Orchestrator versions are 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1.

The authors of the Arista advisory point out that VCO is accessible from the network by default. There is no configuration that can prevent this. However, attackers need access to the VCO web interface; no further credentials are required. The warning also lists some indications of successful attacks and admits that the security advisory was based on active exploitation of the vulnerability and subsequent external detection.

Fortinet admins have been able to patch the vulnerability since February. They should catch up on this at the latest now, if necessary. Furthermore, IT administrators should assume that their devices have been compromised and initiate corresponding investigations if they can only install the updates now. This is particularly recommended for the Arista vulnerability, as the patches were released only after the exploitation was discovered.

In mid-June, it became known that 74,000 Fortinet appliances were cracked in multiple ways . The phenomenon has been codenamed “FortiBleed”.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.