CISA has added two more vulnerabilities to its Known Exploited Vulnerabilities catalog, the US government running list of bugs that attackers are already using against real targets. Both sit in equipment that guards the edge of corporate networks: Fortinet FortiOS and Arista VeloCloud Orchestrator On-Prem.
They are not equal priority, and CISA's own deadlines say so: the Arista flaw had to be remediated by July 30, 2026, the Fortinet one by August 10, 2026.
Patch first: CVE-2026-16812, an OS command injection flaw in Arista VeloCloud Orchestrator On-Prem, the self-hosted management console for VeloCloud SD-WAN. Arista scores it 10.0 Critical on CVSS v3.1 and v4.0, and states that VCO tenant or operator credentials are not required, so exploitation is unauthenticated. It exposes internal-only functionality that, in Arista's words, is not intended to be remotely accessible, letting a remote attacker run commands on the VCO host. Arista confirms active exploitation and publishes indicators: check VCO web access logs for the source addresses 8[.]19[.]75[.]217, 206[.]72[.]242[.]124 and 206[.]72[.]242[.]162. Fixed in VCO 5.2.3.14, 6.1.3.4, 6.4.2.4 and 7.0.0.1.
Then CVE-2025-68686, which is a far smaller problem than its catalog title suggests. CISA lists it as an exposure of sensitive information, but Fortinet's own advisory FG-IR-25-934 titles it "SSL-VPN Symlink Persistence Patch Bypass" and describes it as a patch bypass for persistence abused in a post-exploit scenario. Fortinet rates it Medium (CVSS v3.1 base 5.9, shown as 5.3 on Fortinet's portal with temporal metrics applied). Crucially it is not independently exploitable: Fortinet says it can only be abused as a consequence of a threat actor exploiting a known vulnerability to gain read-only filesystem access, and CISA's own entry repeats that an attacker would need to have compromised the product via another vulnerability first. Devices that never had SSL-VPN enabled are not affected. It is a persistence mechanism for an intruder who is already in, not a way in.
What the listing tells you
CISA does not publish exploitation detail or attribution when it adds an entry, so the listing itself is the signal. Both bugs were added on the basis of evidence of active exploitation, not on theoretical severity, which is precisely why the catalog is a better patching queue than a CVSS score. Vendor detail was published, but only in the advisories themselves rather than in the CISA alert: Arista's Security Advisory 0144 names attacker source addresses and tells operators to review VCO web access logs, and Fortinet's FG-IR-25-934 gives the exploitation precondition, the affected and fixed release matrix and a virtual patch. The scale of exploitation is genuinely unpublished, so treat that absence as a gap in public reporting rather than as evidence that exploitation is limited.
Why edge devices keep landing here
Network edge appliances are attractive for a reason. They are internet-facing by design, they hold credentials and routing authority for everything behind them, and they usually sit outside the endpoint detection tooling deployed everywhere else, so a compromise can run quietly for weeks. Fortinet equipment in particular has become a fixture in both the catalog and in ransomware intrusion chains. IntelFusions covered the exploitation of unauthenticated API flaws in Fortinet FortiSandbox in June, and CISA flagged four more exploited flaws only days ago.
What you should do
Federal civilian agencies are bound by Binding Operational Directive 26-04, which requires them to prioritize rapid remediation of catalog-listed flaws on publicly exposed assets that grant total control after exploitation, while deferring lower-risk items. The directive also sets an expectation that agencies check whether a system was compromised before the patch was applied. That step matters here: patching a device that has been exploited for weeks closes the door but does not evict anyone already inside.
Everyone else is not bound by BOD 26-04, but the logic carries. Establish whether you run FortiOS or an on-premises VeloCloud Orchestrator, apply the vendor fixed release, and treat any internet-exposed instance as suspect until you have reviewed authentication logs, administrator accounts, scheduled tasks and configuration changes going back at least to the start of the month. Where a device cannot be patched immediately, pull its management interface off the public internet and restrict access to a jump host. CISA encourages all organizations, not just agencies, to run their vulnerability management off the catalog.
Primary source: Cisa.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.