
Recently, CISA added two vulnerabilities affecting Fortinet FortiOS and Arista VeloCloud Orchestrator to its Known Exploited Vulnerabilities (KEV) catalog. CISA’s move highlights the need for organizations to review affected systems and prioritize remediation.
However, the two flaws carry different risks, so security teams must understand each vulnerability before responding.
What Is Happening With the Fortinet and Arista Vulnerabilities?
On the 27th of July, CISA added CVE-2025-68686 and CVE-2026-16812 to its catalog due to evidence of active exploitation.
On one hand, CVE-2026-16812 affects VeloCloud Orchestrator on-premises and hosted versions. Arista classifies it as an OS command injection flaw and assigns it a CVSS score of 10.0. Successful exploitation can give a remote attacker access to privileged internal functionality and affect the VCO host.
On the other hand, CVE-2025-68686 affects FortiOS. Fortinet describes it as an SSL-VPN symbolic-link persistence patch bypass. The flaw can expose information, but an attacker first needs filesystem-level access through another vulnerability.
Why Is CISA Prioritizing the Vulnerabilities?
CISA uses its KEV catalog to identify vulnerabilities with evidence of exploitation. Therefore, the catalog gives security teams a way to prioritize flaws already appearing in attacks.
In addition, CISA sets specific remediation deadlines and federal agencies face specific requirements for KEV entries. The deadline for CVE-2026-16812 was July 30, 2026. Meanwhile, CVE-2025-68686 carried an August 10, 2026 deadline.
CISA’s deadlines target Federal Civilian Executive Branch agencies. However, other organizations can still use the catalog to guide risk-based vulnerability management and patching priorities.
Why Do the Vulnerabilities Matter?
At the moment, the Arista vulnerability creates a serious concern because successful exploitation can compromise the confidentiality, integrity, and availability of VCO and its managed data. Also, Arista says the vulnerable functionality remains exposed by default.
Moreover, attackers do not need VCO tenant or operator credentials. They only need network access to the VCO web interface. Arista has also observed attacks from three IP addresses and recommends reviewing logs for suspicious activity.
However, the Fortinet vulnerability presents a different situation. Fortinet currently lists its known exploitation status as “No.” Therefore, organizations should not describe CVE-2025-68686 as independently confirmed active exploitation based on Fortinet’s advisory. Instead, the flaw can help an attacker bypass a protection after another vulnerability provides filesystem access.
What Comes Next for Organizations?
Now, organizations should first identify affected VCO and FortiOS versions. CISA and Arista recommend upgrading affected VCO installations to fixed releases as soon as possible. Fixed versions include VCO 5.2.3.14, 6.1.3.4, and 6.4.2.4.
Until administrators deploy fixes, Arista recommends restricting VCO web access to trusted administrative networks. Teams should also monitor unexpected activity and review web, application, system, and database logs.
In addition, Fortinet users should check affected FortiOS releases against the vendor’s advisory and apply the recommended fixes. Security teams should also investigate signs of earlier compromise when evidence warrants it.
Ultimately, patching remains the priority, but organizations should not stop there. They should review exposure, examine suspicious activity, and strengthen access controls around affected management systems.
