www.heise.de Critical Vulnerabilities in FortiOS and Arista VeloCloud Under Active Exploitation
Article Content
- •FortiOS and VeloCloud have critical vulnerabilities under active exploitation.
- •CVE-2025-68686 allows unauthorized access to confidential data in FortiOS.
- •CVE-2026-16812 enables attackers to access internal functions in VeloCloud without credentials.
Fortinet's FortiOS and Arista's VeloCloud Orchestrator On-Prem are currently under attack due to critical vulnerabilities. The FortiOS vulnerability (CVE-2025-68686) allows unauthorized access to confidential information via manipulated HTTP requests, affecting versions 6.4 to 7.6. Arista's VeloCloud (CVE-2026-16812) has a critical flaw that allows attackers to access internal functions without proper credentials. The US CISA has confirmed active exploitation of both vulnerabilities as of July 27, 2026. Fortinet has released patches for affected FortiOS versions, while Arista has provided updates for VeloCloud. IT administrators are urged to act quickly to mitigate risks, especially for the VeloCloud vulnerability, which was exploited before patches were available. Security experts recommend assuming devices may have been compromised if updates are not applied immediately.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Fortinet and CVE-2025-68686 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Multiple Ransomware Attacks Target Diverse Industries in September 2026 In early September 2026, several ransomware groups executed attacks on various organizations, including Krybit's assault on Reignwood Park Thailand and Arab Maritime Petroleum Transport Company, Everest's attack on VIVOTEK, and Settra's targeting of Golden Neo Life. These incidents involved threats to leak sensitive…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…