Back Securityaffairs U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known ...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities (KEV) catalog .
Below are the flaws added to the KeV catalog:
CVE-2025-68686 is an information disclosure vulnerability affecting multiple versions of Fortinet FortiOS. The flaw allows a remote, unauthenticated attacker to bypass a security patch designed to prevent the persistence of malicious symbolic links that attackers may leave behind after compromising a device.
The vulnerability cannot be exploited on its own. An attacker must first gain filesystem-level access to the FortiOS appliance by exploiting a separate vulnerability. Once the system has already been compromised, specially crafted HTTP requests can be used to bypass the symbolic link protection introduced by Fortinet, potentially exposing sensitive information that should no longer be accessible. In essence, the flaw weakens the effectiveness of the earlier mitigation, allowing attackers who have already established a foothold on the device to continue accessing protected resources or maintain aspects of their post-exploitation activity.
The vulnerability CVE-2026-16812 affects the on-premises VMware VeloCloud Orchestrator (VCO) and exposes privileged internal functionality that was intended to be accessible only by trusted internal components. Due to this flaw, a remote attacker can invoke these internal functions, potentially gaining unauthorized access to the underlying VCO host.
Successful exploitation could compromise the confidentiality, integrity, and availability of both the orchestrator and the network data it manages, enabling attackers to access sensitive information, modify configurations, or disrupt SD-WAN management operations. VMware has confirmed that the flaw is actively exploited in the wild. The Hosted and Dedicated VCO offerings were patched before public disclosure, while organizations running on-premises deployments should apply the available security updates as soon as possible.
Arista said the vulnerability was discovered externally and is being actively exploited, but did not disclose when it was reported or how many customers may have been affected. The company also published three IP addresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to block them and check logs for signs of compromise.
“If compromise is suspected, operators should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible.” reads the company’s advisory .
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities , FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the Arista VeloCloud Orchestrator flaw by July 20, 2026, and the Fortinet FortiOS flaw by August 10, 2026.
Follow me on Twitter: @securityaffairs and and Mastodon
( SecurityAffairs – hacking, CISA )
Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.
Researchers uncovered the 200,000-device Dysphoria botnet, which uses Ethereum and Solana domains to hide its…
JetBrains patched a critical TeamCity flaw (CVE-2026-63077) enabling unauthenticated code execution on affected on-premise servers.…
Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple…
Reuters says OpenAI failed to detect its AI agent hacking Hugging Face for days, discovering…
MedusaHVNC RAT uses hidden Windows desktops to remotely control browsers, steal data, and evade detection…
DentaQuest disclosed a data breach that may have exposed the personal and dental health information…
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
