CISA adding Fortinet FortiOS and Arista VeloCloud Orchestrator vulnerabilities to the Known Exploited Vulnerabilities catalog is a clear warning that defenders should treat these issues as active operational risk, not routine patch-management noise.

The CISA Known Exploited Vulnerabilities catalog is important because it is based on evidence of exploitation in the wild. These are not just vulnerabilities with high scores or scary descriptions. They are vulnerabilities that attackers are already using or have been observed exploiting. That changes the priority immediately.

The two vulnerabilities added on July 27, 2026, affect security and network-management infrastructure. That is what makes this update especially serious. FortiOS runs on Fortinet security appliances, while VeloCloud Orchestrator is used to centrally manage SD-WAN environments. These are not ordinary endpoints. They are control points for traffic, access, policy, routing, remote connectivity, and visibility.

The Fortinet vulnerability, tracked as CVE-2025-68686, is an exposure-of-sensitive-information issue in FortiOS. It affects multiple FortiOS versions and may allow a remote unauthenticated attacker to bypass a patch-related mechanism through crafted HTTP requests. Sensitive information exposure on a firewall or VPN platform is not a minor concern, because these devices may contain configuration data, VPN details, authentication settings, certificates, routes, policies, and other information useful to attackers.

Firewall and VPN configuration data can be extremely valuable. It may reveal internal network structure, trusted IP ranges, NAT rules, allowed services, remote-access paths, administrator settings, VPN relationships, and security-control weaknesses. Even if the vulnerability does not directly provide full command execution, leaked configuration or security information can help attackers plan better follow-on attacks.

The Arista vulnerability, tracked as CVE-2026-16812, affects on-premises VeloCloud Orchestrator deployments and is reported as an unauthenticated OS command-injection flaw. That is a much more direct control-plane risk. If attackers can execute operating-system commands on the orchestrator, they may be able to compromise the confidentiality, integrity, and availability of the orchestration platform and the data it manages.

VeloCloud Orchestrator is used to configure, monitor, and manage SD-WAN deployments and edge devices. A compromise of this layer can be more serious than compromise of one branch device, because the orchestrator has a broader view and management role across the network. Attackers understand this perfectly. Why attack one lock when you can attack the person holding the keyring?

Organizations should immediately identify whether they use affected FortiOS versions or on-premises VeloCloud Orchestrator deployments. Asset inventory is the first step. This should include production systems, disaster-recovery systems, lab systems, older appliances, standby nodes, managed-service deployments, and forgotten internet-facing instances. The forgotten one is usually the one quietly waving at attackers from the public internet.

For Fortinet environments, administrators should review FortiOS versions, confirm vendor guidance, apply available fixes, and evaluate whether any device had management or VPN interfaces exposed to untrusted networks. Internet-facing firewall management interfaces should be treated as high-risk exposure and restricted immediately.

Security teams should review Fortinet appliance logs for suspicious HTTP requests, unexpected configuration access, unusual administrator activity, new accounts, configuration exports, VPN changes, authentication changes, and abnormal traffic around the affected devices. Any signs of information disclosure should trigger deeper review of exposed credentials and configuration data.

If sensitive firewall configuration was accessed, organizations should consider rotating exposed secrets, certificates, API tokens, VPN credentials, administrator credentials, and other trust material. A firewall configuration file can contain enough clues to support future attacks even after the vulnerability is patched.

For Arista VeloCloud Orchestrator, the response should be urgent. A maximum-severity unauthenticated command-injection vulnerability on an SD-WAN orchestrator is exactly the kind of issue that should jump ahead of ordinary maintenance. Administrators should apply fixed versions immediately and confirm that the running environment is actually updated.

Access to the VCO web interface should be restricted to trusted administrative networks wherever possible. Public or broad network exposure of management planes should be reduced. If the orchestrator must be reachable, access should be limited through VPN, zero-trust access, IP allowlisting, strong authentication, and monitoring.

Because exploitation has been reported, patching alone is not enough. Organizations should perform compromise assessment on exposed VeloCloud Orchestrator systems. Security teams should review application logs, web logs, operating-system logs, process execution history, file changes, administrator activity, configuration changes, and outbound network connections.

Defenders should look for signs of command execution, newly created files, suspicious scripts, unknown services, cron jobs, web shells, unexpected child processes, unfamiliar outbound connections, and changes to orchestrator configuration. A management server can continue to look operational while quietly carrying attacker persistence. This is why “it still works” remains one of the weakest incident-response conclusions ever invented.

Configuration integrity should be reviewed. For SD-WAN environments, unauthorized changes to routes, policies, tunnels, device profiles, administrator accounts, tenant settings, or monitoring configuration can create wider network impact. Administrators should compare current configuration with known-good baselines and approved change records.

Credential review is essential. Orchestrators and firewalls often store or access sensitive credentials, certificates, tokens, service accounts, and integration secrets. If these platforms were exploited, downstream credentials may need to be rotated from clean systems. Removing an exploit while leaving stolen credentials active is just closing the front door after handing out spare keys.

Organizations should also review connected systems. Fortinet and VeloCloud platforms may integrate with SIEM tools, identity providers, automation systems, backup platforms, ticketing systems, monitoring tools, and managed-service environments. A compromise of the network-security layer can expose or affect those connected trust paths.

For managed service providers, this update is especially important. MSPs and MSSPs may manage multiple customer networks through centralized security or SD-WAN infrastructure. A single vulnerable management plane can create risk across many customers. That makes patching, access restriction, tenant separation, logging, and customer communication critical.

CISA KEV additions should be built directly into vulnerability management workflows. When a vulnerability appears in KEV, organizations should not wait for normal CVSS-based prioritization alone. Active exploitation should override ordinary patch queues. The attackers have already done the prioritization for you, which is generous in the least comforting way possible.

Organizations should maintain a process to review CISA KEV updates daily, map affected products to internal assets, assign owners, apply fixes, validate completion, and perform hunting where exploitation is possible. The process should include network appliances, cloud services, security tools, edge devices, collaboration systems, identity platforms, and developer infrastructure.

Network and security appliances should also be included in endpoint-style monitoring where possible. Too many organizations log servers and workstations but have limited visibility into appliances that sit directly at the edge. Attackers know these blind spots exist and repeatedly target them.

The broader lesson is that security infrastructure is now a prime target. Firewalls, VPNs, SD-WAN orchestrators, security managers, remote-access systems, and monitoring platforms are attractive because they hold trust, visibility, credentials, and control. If attackers compromise the tools used to defend or manage the network, they may gain a stronger position than they would from compromising a normal endpoint.

The key lesson is simple: KEV means act now. These vulnerabilities have crossed the line from possible risk to observed exploitation.

Organizations using affected Fortinet FortiOS or Arista VeloCloud Orchestrator systems should patch immediately, restrict management exposure, hunt for compromise, review configuration integrity, rotate exposed secrets where needed, and monitor for follow-on activity.

A firewall or SD-WAN orchestrator is not just another appliance. It is part of the enterprise control plane. When that layer is vulnerable and attackers are already exploiting it, the response must be fast, disciplined, and suspicious. Anything less gives attackers exactly what they want: trusted infrastructure doing untrusted work.


CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities . CISA will continue to add vulnerabilities to the catalog that meet the specified criteria . Aware of an exp

Source: CISA Adds Two Known Exploited Vulnerabilities to Catalog via CISA Advisories — published 27 Jul 2026.