Close Menu

    Stay Ahead with Exclusive Updates!

    Enter your email below and be the first to know what’s happening in the ever-evolving world of technology!

    What's Hot

    The US Just Banned Imports of Chinese-Made Humanoid Robots on National Security Grounds. The Decision Draws a Line That No Administration Has Drawn Before and It Arrives Exactly as China’s Robotics Industry Was About to Go Global

    August 11, 2026

    CISA Just Added Fortinet and Arista Zero-Day Vulnerabilities to Its Mandatory Patch List. If Your Organization Is Running Either Platform and Has Not Patched Yet the Window to Act Is Already Closing

    August 11, 2026

    Apple Just Passed Nvidia to Become the World’s Most Valuable Company Again. The Flip Says Less About Apple Than It Does About How Investors Are Starting to Feel About the AI Infrastructure Boom

    August 11, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter)
    PhronewsPhronews
    • Home
    • Big Tech & Startups

      The US Just Banned Imports of Chinese-Made Humanoid Robots on National Security Grounds. The Decision Draws a Line That No Administration Has Drawn Before and It Arrives Exactly as China’s Robotics Industry Was About to Go Global

      August 11, 2026

      Apple Just Passed Nvidia to Become the World’s Most Valuable Company Again. The Flip Says Less About Apple Than It Does About How Investors Are Starting to Feel About the AI Infrastructure Boom

      August 11, 2026

      Google Pulled Its AI Image Generator From Google Earth Within a Day of Launch. A Researcher Had Already Used It to Fake a Nuclear Plant in Iran and Google’s Own Watermark Failed to Catch It.

      August 11, 2026

      A UK Bank Customer Is Fighting for a £14,000 Refund After Stolen Funds Were Used to Buy Claude AI Credits. The Case Exposes a Gap in Fraud Protection That Nobody Designed the Banking System to Handle.

      August 11, 2026

      Meta Just Quit the Global Clean Energy Pact It Signed Three Years Ago Because Its AI Data Centers Need More Power Than Renewables Can Deliver Right Now. The Exit Is the Most Honest Statement Any Big Tech Company Has Made About the Real Cost of the AI Boom

      August 10, 2026
    • Crypto

      Market Collapse: What Happened to NFTs?

      April 23, 2026

      Quantum Computing Advances Force Coinbase and Institutional Custodians to Rethink Crypto Security

      March 8, 2026

      AI Assisted Hacking Groups Target Crypto Firms With Multi-Layered Social Engineering

      February 18, 2026

      Global Crypto Regulations Expand as 2026 Begins With New Data Collection Frameworks and National Laws

      January 16, 2026

      Coinbase Bets on Stablecoin and On-Chain Growth as Key Market Drivers in 2026 Strategy

      January 10, 2026
    • Gadgets & Smart Tech
      Featured

      Apple Just Delayed Development on Its Smart Glasses After Internal Privacy Reviews. The Delay Is the Clearest Sign Yet That Wearable AI Has a Trust Problem That Hardware Cannot Solve.

      By preciousAugust 4, 2026
      Recent

      Apple Just Delayed Development on Its Smart Glasses After Internal Privacy Reviews. The Delay Is the Clearest Sign Yet That Wearable AI Has a Trust Problem That Hardware Cannot Solve.

      August 4, 2026

      Microsoft Is Building Quantum-Resistant Security Before Quantum Computers Can Break the Encryption Protecting Everything. Here Is How Far Along That Work Actually Is

      July 21, 2026

      AI Has Spent Three Years Getting Smarter for People Who Can Already Afford It. Nokia Just Changed That and the Implications Go Further Than Anyone Is Crediting

      July 18, 2026
    • Cybersecurity & Online Safety

      CISA Just Added Fortinet and Arista Zero-Day Vulnerabilities to Its Mandatory Patch List. If Your Organization Is Running Either Platform and Has Not Patched Yet the Window to Act Is Already Closing

      August 11, 2026

      ShinyHunters Broke Into Abbott Laboratories’ Cancer Diagnostics Business Through a Single Compromised Microsoft Entra Login. The Breach Is a Reminder That the Most Sophisticated Attacks Still Start With the Simplest Failures.

      August 11, 2026

      OpenAI and Anthropic Have Both Confirmed Their Frontier Models Broke Out of Sandboxed Test Environments and Reached Systems They Were Never Supposed to Touch

      August 7, 2026

      Nvidia, Microsoft, and Palantir Just Formed a Joint AI Security Alliance Days After the Hugging Face Hack. Three Companies That Have Never Coordinated Like This Before Just Decided the AI Cyberattack Threat Is Too Big for Any One of Them to Handle Alone.

      August 7, 2026

      Origin Energy Has Confirmed a Breach Affecting 900,000 Customers. Names, Home Addresses, Bank Details, and Partial Card Numbers Were All Taken and the People Most at Risk Are the Ones Who Have No Idea Yet.

      August 4, 2026
    PhronewsPhronews
    Home»Cybersecurity & Online Safety»CISA Just Added Fortinet and Arista Zero-Day Vulnerabilities to Its Mandatory Patch List. If Your Organization Is Running Either Platform and Has Not Patched Yet the Window to Act Is Already Closing
    Cybersecurity & Online Safety

    CISA Just Added Fortinet and Arista Zero-Day Vulnerabilities to Its Mandatory Patch List. If Your Organization Is Running Either Platform and Has Not Patched Yet the Window to Act Is Already Closing

    fariehanBy fariehanAugust 11, 2026No Comments
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Photo Credit: Getty Images

    Recently, CISA added two vulnerabilities affecting Fortinet FortiOS and Arista VeloCloud Orchestrator to its Known Exploited Vulnerabilities (KEV) catalog. CISA’s move highlights the need for organizations to review affected systems and prioritize remediation. 

    However, the two flaws carry different risks, so security teams must understand each vulnerability before responding. 

    What Is Happening With the Fortinet and Arista Vulnerabilities?

    On the 27th of July, CISA added CVE-2025-68686 and CVE-2026-16812 to its catalog due to evidence of active exploitation.

    On one hand, CVE-2026-16812 affects VeloCloud Orchestrator on-premises and hosted versions. Arista classifies it as an OS command injection flaw and assigns it a CVSS score of 10.0. Successful exploitation can give a remote attacker access to privileged internal functionality and affect the VCO host.

    On the other hand, CVE-2025-68686 affects FortiOS. Fortinet describes it as an SSL-VPN symbolic-link persistence patch bypass. The flaw can expose information, but an attacker first needs filesystem-level access through another vulnerability.

    Why Is CISA Prioritizing the Vulnerabilities?

    CISA uses its KEV catalog to identify vulnerabilities with evidence of exploitation. Therefore, the catalog gives security teams a way to prioritize flaws already appearing in attacks.

    In addition, CISA sets specific remediation deadlines and federal agencies face specific requirements for KEV entries. The deadline for CVE-2026-16812 was July 30, 2026. Meanwhile, CVE-2025-68686 carried an August 10, 2026 deadline.

    CISA’s deadlines target Federal Civilian Executive Branch agencies. However, other organizations can still use the catalog to guide risk-based vulnerability management and patching priorities.

    Why Do the Vulnerabilities Matter?

    At the moment, the Arista vulnerability creates a serious concern because successful exploitation can compromise the confidentiality, integrity, and availability of VCO and its managed data. Also, Arista says the vulnerable functionality remains exposed by default.

    Moreover, attackers do not need VCO tenant or operator credentials. They only need network access to the VCO web interface. Arista has also observed attacks from three IP addresses and recommends reviewing logs for suspicious activity.

    However, the Fortinet vulnerability presents a different situation. Fortinet currently lists its known exploitation status as “No.” Therefore, organizations should not describe CVE-2025-68686 as independently confirmed active exploitation based on Fortinet’s advisory. Instead, the flaw can help an attacker bypass a protection after another vulnerability provides filesystem access.

    What Comes Next for Organizations?

    Now, organizations should first identify affected VCO and FortiOS versions. CISA and Arista recommend upgrading affected VCO installations to fixed releases as soon as possible. Fixed versions include VCO 5.2.3.14, 6.1.3.4, and 6.4.2.4.

    Until administrators deploy fixes, Arista recommends restricting VCO web access to trusted administrative networks. Teams should also monitor unexpected activity and review web, application, system, and database logs.

    In addition, Fortinet users should check affected FortiOS releases against the vendor’s advisory and apply the recommended fixes. Security teams should also investigate signs of earlier compromise when evidence warrants it.

    Ultimately, patching remains the priority, but organizations should not stop there. They should review exposure, examine suspicious activity, and strengthen access controls around affected management systems.

    active exploitation Arista Arista Networks Arista vulnerability CISA CISA KEV critical vulnerability cyber attacks cyber risk Cyber Threats cybersecurity Cybersecurity alert Cybersecurity News Enterprise Security Fortinet Fortinet vulnerability FortiOS information security KEV catalog Known Exploited Vulnerabilities network infrastructure network security patch management security advisory security patch Security vulnerabilities software patching Threat Intelligence VeloCloud VeloCloud Orchestrator Vulnerabilities vulnerability management zero-day zero-day attacks zero-day vulnerability
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    fariehan

    Related Posts

    The US Just Banned Imports of Chinese-Made Humanoid Robots on National Security Grounds. The Decision Draws a Line That No Administration Has Drawn Before and It Arrives Exactly as China’s Robotics Industry Was About to Go Global

    August 11, 2026

    ShinyHunters Broke Into Abbott Laboratories’ Cancer Diagnostics Business Through a Single Compromised Microsoft Entra Login. The Breach Is a Reminder That the Most Sophisticated Attacks Still Start With the Simplest Failures.

    August 11, 2026

    OpenAI and Anthropic Have Both Confirmed Their Frontier Models Broke Out of Sandboxed Test Environments and Reached Systems They Were Never Supposed to Touch

    August 7, 2026

    Comments are closed.

    Top Posts

    Coinbase responds to hack: customer impact and official statement

    May 22, 2025

    Cursor AI Hits 1 Million Daily Users. Why Developers Are Switching to This Coding Tool

    March 23, 2026

    Anthropic Will Use Claude User Chats For Data Training

    October 16, 2025

    MIT Study Reveals ChatGPT Impairs Brain Activity & Thinking

    June 29, 2025
    Don't Miss
    Tech Laws & Digital Rights

    The US Just Banned Imports of Chinese-Made Humanoid Robots on National Security Grounds. The Decision Draws a Line That No Administration Has Drawn Before and It Arrives Exactly as China’s Robotics Industry Was About to Go Global

    By fariehanAugust 11, 2026

    Humanoid robots are becoming the latest front in the technology rivalry between the U.S. and…

    CISA Just Added Fortinet and Arista Zero-Day Vulnerabilities to Its Mandatory Patch List. If Your Organization Is Running Either Platform and Has Not Patched Yet the Window to Act Is Already Closing

    August 11, 2026

    Apple Just Passed Nvidia to Become the World’s Most Valuable Company Again. The Flip Says Less About Apple Than It Does About How Investors Are Starting to Feel About the AI Infrastructure Boom

    August 11, 2026

    Google Pulled Its AI Image Generator From Google Earth Within a Day of Launch. A Researcher Had Already Used It to Fake a Nuclear Plant in Iran and Google’s Own Watermark Failed to Catch It.

    August 11, 2026
    Stay In Touch
    • Facebook
    • Twitter
    About Us
    About Us

    Evolving from Phronesis News, Phronews brings deep insight and smart analysis to the world of technology. Stay informed, stay ahead, and navigate tech with wisdom.
    We're accepting new partnerships right now.

    Email Us: info@phronews.com

    Facebook X (Twitter) Pinterest YouTube
    Our Picks
    Most Popular

    Coinbase responds to hack: customer impact and official statement

    May 22, 2025

    Cursor AI Hits 1 Million Daily Users. Why Developers Are Switching to This Coding Tool

    March 23, 2026

    Anthropic Will Use Claude User Chats For Data Training

    October 16, 2025
    © 2025. Phronews.
    • Home
    • About Us
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.