CISA says hackers are exploiting Fortinet and Arista flaws

CISA has added two more vulnerabilities to its Known Exploited Vulnerabilities catalog, the US government running list of bugs that attackers are already using against real targets. Both sit in equipment that guards the edge of corporate networks: Fortinet FortiOS and Arista VeloCloud Orchestrator On-Prem.

The first, CVE-2025-68686, is an exposure of sensitive information to an unauthorized actor in FortiOS, the operating system behind Fortinet FortiGate firewalls. Flaws in that class typically leak configuration data, tokens or credentials to someone who should not be able to read them, which in practice hands an attacker the material needed for the next step of an intrusion.

The second, CVE-2026-16812, is an OS command injection flaw in Arista VeloCloud Orchestrator On-Prem, the self-hosted management console for VeloCloud SD-WAN deployments. Command injection means an attacker can make the appliance run commands of their choosing on the underlying system. On a box that manages a wide-area network and holds routing authority over branch sites, that is close to a worst case.

What the listing tells you

CISA does not publish exploitation detail or attribution when it adds an entry, so the listing itself is the signal. Both bugs were added on the basis of evidence of active exploitation, not on theoretical severity, which is precisely why the catalog is a better patching queue than a CVSS score. Neither vendor advisory detail nor the scale of exploitation was included in the alert, so treat the absence of published detail as a gap in public reporting rather than as evidence that exploitation is limited.

Why edge devices keep landing here

Network edge appliances are attractive for a reason. They are internet-facing by design, they hold credentials and routing authority for everything behind them, and they usually sit outside the endpoint detection tooling deployed everywhere else, so a compromise can run quietly for weeks. Fortinet equipment in particular has become a fixture in both the catalog and in ransomware intrusion chains. IntelFusions covered the exploitation of unauthenticated API flaws in Fortinet FortiSandbox in June, and CISA flagged four more exploited flaws only days ago.

What you should do

Federal civilian agencies are bound by Binding Operational Directive 26-04, which requires them to prioritize rapid remediation of catalog-listed flaws on publicly exposed assets that grant total control after exploitation, while deferring lower-risk items. The directive also sets an expectation that agencies check whether a system was compromised before the patch was applied. That step matters here: patching a device that has been exploited for weeks closes the door but does not evict anyone already inside.

Everyone else is not bound by BOD 26-04, but the logic carries. Establish whether you run FortiOS or an on-premises VeloCloud Orchestrator, apply the vendor fixed release, and treat any internet-exposed instance as suspect until you have reviewed authentication logs, administrator accounts, scheduled tasks and configuration changes going back at least to the start of the month. Where a device cannot be patched immediately, pull its management interface off the public internet and restrict access to a jump host. CISA encourages all organizations, not just agencies, to run their vulnerability management off the catalog.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions