www.heise.de
Critical Vulnerabilities in FortiOS and Arista VeloCloud Under Active Exploitation
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Fortinet's FortiOS and Arista's VeloCloud Orchestrator On-Prem are currently under attack due to critical vulnerabilities. The FortiOS vulnerability (CVE-2025-68686) allows unauthorized access to confidential information via manipulated HTTP requests, affecting versions 6.4 to 7.6. Arista's VeloCloud (CVE-2026-16812) has a critical flaw that allows attackers to access internal functions without proper credentials. The US CISA has confirmed active exploitation of both vulnerabilities as of July 27, 2026. Fortinet has released patches for affected FortiOS versions, while Arista has provided updates for VeloCloud. IT administrators are urged to act quickly to mitigate risks, especially for the VeloCloud vulnerability, which was exploited before patches were available. Security experts recommend assuming devices may have been compromised if updates are not applied immediately.
Key Points: • FortiOS and VeloCloud have critical vulnerabilities under active exploitation. • CVE-2025-68686 allows unauthorized access to confidential data in FortiOS. • CVE-2026-16812 enables attackers to access internal functions in VeloCloud without credentials.