Critical Vulnerabilities in FortiOS and Arista VeloCloud Under Active Exploitation

Critical Vulnerabilities in FortiOS and Arista VeloCloud Under Active Exploitation

First seen 28 Jul 2026, 21:24 UTC Heise.Defortiguard.fortinet.comwww.heise.de 83% similarity 78.0

Article Content

Browse articles
ThreatCluster

Fortinet's FortiOS and Arista's VeloCloud Orchestrator On-Prem are currently under attack due to critical vulnerabilities. The FortiOS vulnerability (CVE-2025-68686) allows unauthorized access to confidential information via manipulated HTTP requests, affecting versions 6.4 to 7.6. Arista's VeloCloud (CVE-2026-16812) has a critical flaw that allows attackers to access internal functions without proper credentials. The US CISA has confirmed active exploitation of both vulnerabilities as of July 27, 2026. Fortinet has released patches for affected FortiOS versions, while Arista has provided updates for VeloCloud. IT administrators are urged to act quickly to mitigate risks, especially for the VeloCloud vulnerability, which was exploited before patches were available. Security experts recommend assuming devices may have been compromised if updates are not applied immediately.

Key Points: • FortiOS and VeloCloud have critical vulnerabilities under active exploitation. • CVE-2025-68686 allows unauthorized access to confidential data in FortiOS. • CVE-2026-16812 enables attackers to access internal functions in VeloCloud without credentials.

ThreatCluster AI How this analysis works

Timeline

2026-02-10
CVE-2025-68686 published
Fortinet disclosed a vulnerability in FortiOS affecting SSL VPN, allowing unauthorized data access.
Heise.De
2026-07-27
CVE-2026-16812 published
Arista announced a critical vulnerability in VeloCloud Orchestrator allowing unauthorized access to internal functions.
Heise.De
2026-07-27
CISA confirms active exploitation
CISA added CVE-2025-68686 and CVE-2026-16812 to its Known Exploited Vulnerabilities list due to active attacks.
Heise.De
2026-07-28
Patches released for FortiOS and VeloCloud
Fortinet and Arista released patches for their respective vulnerabilities; admins urged to update immediately.
Heise.De

Community

Browse all →