Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

U.S. CISA Adds Arista VeloCloud Orchestrator and Fortinet FortiOS Flaws to Its Known Exploited Vulnerabilities Catalog: A Growing Concern for Cybersecurity



U.S. CISA has added two new vulnerabilities, Arista VeloCloud Orchestrator and Fortinet FortiOS flaws, to its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities pose significant risks for organizations, emphasizing the importance of timely patching and mitigation strategies. Stay up-to-date with the latest cybersecurity news by following our newsletter and social media channels.

  • Arista VeloCloud Orchestrator and Fortinet FortiOS vulnerabilities have been added to the Known Exploited Vulnerabilities (KEV) catalog by U.S. CISA.
  • The vulnerabilities include CVE-2025-68686, which affects multiple versions of Fortinet FortiOS, and CVE-2026-16812, affecting VMware VeloCloud Orchestrator.
  • Both vulnerabilities are being actively exploited in the wild, with organizations urged to apply available security updates as soon as possible.
  • Organizations must prioritize vulnerability management strategies that focus on patching and mitigation efforts to prevent exploitation by threat actors.
  • CISA orders federal agencies to fix the flaws by July 20, 2026, and August 10, 2026, respectively.



  • U.S. CISA has added Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities (KEV) catalog, a move that highlights the ongoing threat landscape for cybersecurity. The addition of these vulnerabilities to the KEV catalog underscores the importance of prioritizing vulnerability patching and mitigation strategies in organizations.

    The added vulnerabilities include CVE-2025-68686, an information disclosure vulnerability affecting multiple versions of Fortinet FortiOS, with a CVSS score of 5.3. This flaw allows a remote, unauthenticated attacker to bypass security patches designed to prevent the persistence of malicious symbolic links that attackers may leave behind after compromising a device. Furthermore, CVE-2026-16812, an on-premises VMware VeloCloud Orchestrator (VCO) vulnerability with a CVSS score of 10.0, exposes privileged internal functionality intended for trusted internal components only. This flaw enables remote attackers to invoke these functions, potentially gaining unauthorized access to the underlying VCO host.

    These vulnerabilities are being actively exploited in the wild, and organizations running on-premises deployments are urged to apply available security updates as soon as possible. Arista has published three IP addresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to block them and check logs for signs of compromise.

    Experts emphasize that organizations must review the KEV catalog and address vulnerabilities in their infrastructure to prevent exploitation by threat actors. CISA orders federal agencies to fix the Arista VeloCloud Orchestrator flaw by July 20, 2026, and the Fortinet FortiOS flaw by August 10, 2026.

    In light of these additions, organizations must prioritize vulnerability management strategies that focus on patching and mitigation efforts. Effective cybersecurity requires proactive measures to stay ahead of emerging threats like those outlined in the KEV catalog.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/US-CISA-Adds-Arista-VeloCloud-Orchestrator-and-Fortinet-FortiOS-Flaws-to-Its-Known-Exploited-Vulnerabilities-Catalog-A-Growing-Concern-for-Cybersecurity-ehn.shtml

  • https://securityaffairs.com/196130/security/u-s-cisa-adds-arista-velocloud-orchestrator-and-fortinet-fortios-flaws-to-its-known-exploited-vulnerabilities-catalog.html

  • https://nvd.nist.gov/vuln/detail/CVE-2025-68686

  • https://www.cvedetails.com/cve/CVE-2025-68686/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-16812

  • https://www.cvedetails.com/cve/CVE-2026-16812/


  • Published: Tue Jul 28 04:47:13 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us