All incidents

CISA adds Arista VeloCloud and Fortinet FortiOS vulnerabilities to KEV catalogue

vulnerabilityopenJul 27, 2026 — Jul 28, 2026
CISA adds Arista VeloCloud and Fortinet FortiOS vulnerabilities to KEV catalogue

ON 27 July 2026 the Cybersecurity and Infrastructure Security Agency added two new entries to its Known Exploited Vulnerabilities catalogue, one affecting Arista’s VeloCloud Orchestrator and the other affecting Fortinet’s FortiOS operating system. Both flaws are being actively exploited in the wild and allow remote attackers to gain privileged access on compromised devices. The additions follow confirmed reports of command injection and information exposure being used in recent intrusions.

The first entry, tracked as CVE-2026-16812, describes an OS command injection vulnerability in the VeloCloud Orchestrator On‑Prem product. It carries a CVSS v3.1 base score of 10.0, rated critical, and can be triggered over the network without authentication or user interaction. Successful exploitation lets an attacker run arbitrary commands on the underlying host, potentially compromising the confidentiality, integrity and availability of the orchestrator and the networks it manages. Details are available in the CISA catalogue entry here.

The second entry, CVE-2025-68686, concerns an information‑exposure flaw in Fortinet FortiOS that can be accessed via HTTP after an attacker already has file‑system level access to the device. It has a CVSS v3.1 base score of 5.3, rated medium, and allows bypass of a previously applied patch for a symbolic‑link persistence mechanism. Although authentication is not required for the HTTP request, the prerequisite of file‑system compromise limits the attack chain. The CISA catalogue entry is here.

Although CISA has not named any specific threat actors exploiting these flaws, the rapid inclusion in the KEV catalogue indicates that the vulnerabilities are already part of active attack campaigns. The VeloCloud flaw is particularly concerning because it can be triggered from anywhere on the internet and does not require any prior foothold. The FortiOS issue, while needing an initial breach, highlights how attackers chain weaknesses to maintain persistence on edge security appliances. Both issues highlight the importance of keeping perimeter devices up to date.

Arista has also advised customers about two additional vulnerabilities, CVE-2026-17191 and CVE-2026-17192, which affect the same Orchestrator product but require authenticated sessions and are not known to be exploited in the wild. These flaws are rated lower in severity and can be mitigated by restricting administrative access and reviewing system logs for abnormal activity. The vendor’s security advisory provides version‑specific guidance and can be found here.

Defenders should prioritise applying the patches released by Arista for CVE-2026-16812 and the corresponding fix for CVE-2025-68686 from Fortinet as soon as they become available. Where patches are not yet released, organisations should limit orchestrator management interfaces to trusted networks, enforce multi‑factor authentication for administrative accounts and monitor command execution logs for unexpected processes. Network segmentation and regular vulnerability scanning can help reduce the chance that an initial foothold leads to broader compromise.

Intelligence briefing updated Jul 27, 2026

CVE-2026-16812 10.0 KEV CVE-2025-68686 5.3 KEV CVE-2026-17191 CVE-2026-17192
Root sourcewww.arista.com
Timeline Coverage

Swipe to explore timeline