ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-68686CVE-2026-16812

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-68686
Unauthenticated Info-Exposure Bypass of Symlink Patch in Fortinet FortiOS

CVE-2025-68686 is a sensitive-information-exposure flaw (CWE-200) in Fortinet FortiOS that allows a remote, unauthenticated attacker to bypass the vendor's patch for the symbolic-link (symlink) persistency mechanism seen in some post-exploitation cases. It is triggered by crafted HTTP requests sent to a device that has already been compromised through another vulnerability at the filesystem level, for example where symlinks were planted to maintain access to files. By bypassing the patch, the attacker can keep retrieving sensitive information from an otherwise remediated FortiGate device. Any organization running an affected FortiOS release is potentially affected; the CISA data does not enumerate specific versions, so administrators should consult Fortinet's advisory for the affected branches. The flaw was added to CISA's KEV catalog on 2026-07-27, confirming real-world exploitation, and EPSS assigns a 29.6% probability of exploitation within 30 days (98th percentile), with ransomware use currently unknown.

Do: Patch affected FortiOS devices per Fortinet's current advisory, following BOD 26-04 timelines for federal agencies (apply mitigations per vendor instructions or discontinue use where mitigations are unavailable). Because this flaw defeats the earlier symlink-persistence fix, re-check previously remediated devices for residual or recreated symlinks and hunt for indicators of prior filesystem-level compromise, such as unexpected symlinks and anomalous SSL-VPN activity. Review logs for crafted HTTP requests and prioritize internet-facing FortiGate assets for patching and triage.

5.930% KEV
  • Fortinet FortiOS
mass~300,000+ internet-exposed FortiGate/FortiOS devices
CVE-2026-16812
OS Command Injection in Arista VeloCloud Orchestrator On-Prem

Arista VeloCloud Orchestrator (VCO) On-Prem, the centralized management platform for VeloCloud SD-WAN networks, contains an OS command injection vulnerability (CWE-78) that allows a remote attacker to execute operating system commands, reach privileged internal functionality, and impact the underlying VCO host. The available advisory text does not describe the exact injection point or authentication requirements, but the flaw is exploitable remotely against the on-premises orchestrator. A successful attack can compromise the confidentiality, integrity, and availability of the orchestrator and of the configuration and network data it manages. Organizations running an on-premises VeloCloud Orchestrator are affected; CISA scopes the flaw to the on-prem product, provides no version ranges in this data, and no CVSS score has been published yet. The flaw was added to CISA's KEV on 2026-07-27, confirming exploitation in the wild, while ransomware use is unknown, no public proof-of-concept is available, and EPSS currently puts 30-day exploitation probability at 1.6% (74th percentile).

Do: Follow Arista's VeloCloud security advisory: match your on-prem VCO release against the advisory's affected list and apply the fixed update as soon as possible, as required for U.S. federal agencies under BOD 26-04 by the CISA deadline. Until patched, restrict the orchestrator's web/API access to trusted management networks or VPN, verify whether your VCO is internet-exposed, and hunt for signs of unexpected command execution or privileged activity on the VCO host per CISA's forensics triage requirements; if mitigations are unavailable, follow BOD 26-04 guidance on discontinuing use of the product.

10.02% KEV
  • Arista VeloCloud Orchestrator On-Prem
moderate≈1,000–10,000 on-prem orchestrator deployments (the vulnerable management servers), with downstream managed SD-WAN edge fleets far larger

Indicators of compromiseAll →

TypeIndicatorContext
ipv4206.72.242.124shed three IP addresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to block them and ch
ipv4206.72.242.162dresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to block them and check logs for sig
ipv48.19.75.217ny also published three IP addresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to b
Full article517 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the flaws added to the KeV catalog:

  • CVE-2025-68686 (CVSS score of 5.3) Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
  • CVE-2026-16812 (CVSS score of 10.0) Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

CVE-2025-68686 is an information disclosure vulnerability affecting multiple versions of Fortinet FortiOS. The flaw allows a remote, unauthenticated attacker to bypass a security patch designed to prevent the persistence of malicious symbolic links that attackers may leave behind after compromising a device.

The vulnerability cannot be exploited on its own. An attacker must first gain filesystem-level access to the FortiOS appliance by exploiting a separate vulnerability. Once the system has already been compromised, specially crafted HTTP requests can be used to bypass the symbolic link protection introduced by Fortinet, potentially exposing sensitive information that should no longer be accessible. In essence, the flaw weakens the effectiveness of the earlier mitigation, allowing attackers who have already established a foothold on the device to continue accessing protected resources or maintain aspects of their post-exploitation activity.

The vulnerability CVE-2026-16812 affects the on-premises VMware VeloCloud Orchestrator (VCO) and exposes privileged internal functionality that was intended to be accessible only by trusted internal components. Due to this flaw, a remote attacker can invoke these internal functions, potentially gaining unauthorized access to the underlying VCO host.

Successful exploitation could compromise the confidentiality, integrity, and availability of both the orchestrator and the network data it manages, enabling attackers to access sensitive information, modify configurations, or disrupt SD-WAN management operations. VMware has confirmed that the flaw is actively exploited in the wild. The Hosted and Dedicated VCO offerings were patched before public disclosure, while organizations running on-premises deployments should apply the available security updates as soon as possible.

Arista said the vulnerability was discovered externally and is being actively exploited, but did not disclose when it was reported or how many customers may have been affected. The company also published three IP addresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to block them and check logs for signs of compromise.

“If compromise is suspected, operators should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible.” reads the company’s advisory.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the Arista VeloCloud Orchestrator flaw by July 20, 2026, and the Fortinet FortiOS flaw by August 10, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/196130/security/u-s-cisa-adds-arista-velocloud-orchestrator-and-fortinet-fortios-flaws-to-its-known-exploited-vulnerabilities-catalog.html