TL;DR: On July 27, 2026, CISA made two KEV additions. Both are known exploited vulnerabilities. One is a critical Arista VeloCloud RCE, while the other is a FortiOS persistence bypass.
- Product: Arista Networks VeloCloud Orchestrator On-Prem, Fortinet FortiOS
- Vulnerabilities: 2 flaws (CVE-2026-16812, CVE-2025-68686)
- Highest severity: 10.0 (Critical · CVSSv3)
- Worst impact: VeloCloud Orchestrator OS Command Injection
- Status: 2 exploited; patches available
- Action: Update to 5.2.3.14, 6.1.3.4, 6.4.2.4, 7.0.0.1 now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-16812 | 10 | VeloCloud Orchestrator OS Command Injection | 5.2.3.14, 6.1.3.4, 6.4.2.4 (+1) | Exploited |
| CVE-2025-68686 | 5.9 | CWE-200 | — | Exploited |
Why These CISA KEV Additions Matter
A KEV listing means confirmed exploitation, not a guess. CISA added both flaws and set patch deadlines for federal agencies. Still, every organization should treat them as priority fixes. The pairing is telling: one grants full takeover, the other quietly preserves access.
How the Attacks Work
CVE-2026-16812 — Arista VeloCloud Orchestrator
This flaw scores a maximum CVSS 10.0. A remote attacker runs OS commands on the VCO host with no login. Arista confirmed active exploitation in its advisory and even published attacker IP addresses.
CVE-2025-68686 — FortiOS SSL-VPN
By contrast, this medium-severity bug (CVSS 5.3) is a patch bypass. It restores a symlink persistence trick used after an earlier breach. As a result, an attacker keeps read access to sensitive files despite a prior fix. See Fortinet’s PSIRT advisory for the specifics.
Affected Versions
VeloCloud Orchestrator on-prem is affected before 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. Meanwhile, the FortiOS flaw hits 7.6.0–7.6.1, 7.4.0–7.4.6, and all 7.2, 7.0, and 6.4 releases.
Patch and Mitigation Steps
Upgrade both products now. Move VCO to a fixed 5.2, 6.1, 6.4, or 7.0 release. For FortiOS, update to 7.6.2 or 7.4.7, and migrate older trains to a supported build. Because these are known exploited vulnerabilities, patch fast and hunt for signs of earlier compromise.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.