The U.S. Cybersecurity and Infrastructure Security Agency has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, affecting Arista VeloCloud Orchestrator and Fortinet FortiOS products. The more severe flaw, CVE-2026-16812, carries a maximum CVSS score of 10.0 and impacts on-premises deployments of VMware VeloCloud Orchestrator. CVE-2025-68686, affecting Fortinet FortiOS with a CVSS score of 5.3, represents an information disclosure weakness that undermines previous security patches.
The Arista vulnerability exposes privileged internal functionality that should only be accessible to trusted internal components. Remote attackers can invoke these internal functions without authentication, potentially gaining unauthorized access to the underlying VCO host. This access could compromise the confidentiality, integrity, and availability of both the orchestrator platform and the network data it manages. Arista confirmed the flaw is being actively exploited and provided three IP addresses associated with the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) for organizations to block.
The Fortinet vulnerability allows remote, unauthenticated attackers to bypass a security patch designed to prevent malicious symbolic links from persisting after device compromise. The flaw cannot be exploited independently; attackers must first gain filesystem-level access through a separate vulnerability. Once a system is compromised, specially crafted HTTP requests can bypass symbolic link protections, allowing continued access to sensitive information and helping maintain post-exploitation activity.
VMware patched its hosted and dedicated VCO offerings before public disclosure, but organizations running on-premises deployments remain at risk until updates are applied. Arista has not disclosed when the vulnerability was reported or how many customers may be affected. The company recommends that organizations suspecting compromise should preserve web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before beginning remediation efforts.
Under Binding Operational Directive 22-01, federal agencies must remediate the Arista VeloCloud Orchestrator vulnerability by July 20, 2026, and the Fortinet FortiOS flaw by August 10, 2026. CISA strongly recommends that private sector organizations also review the KEV catalog and prioritize patching these vulnerabilities in their infrastructure. Organizations should immediately check for indicators of compromise, apply available security updates, and implement the IP address blocks provided by Arista to reduce exposure to ongoing exploitation attempts.
Source: https://securityaffairs.com/196130/security/u-s-cisa-adds-arista-velocloud-orchestrator-and-fortinet-fortios-flaws-to-its-known-exploited-vulnerabilities-catalog.html


