All stories
criticalAPT / Nation-StateCVE-2025-68686CVE-2026-16812

Unauthenticated attackers exploit command injection flaws in Arista VeloCloud and Fortinet FortiOS

Critical vulnerabilities in Arista VeloCloud Orchestrator and Fortinet FortiOS are currently being exploited in the wild. The Arista flaw allows unauthenticated remote attackers to gain control of the orchestrator host via OS command injection. Prioritize upgrading your Arista VCO instances immediately.

Summary

CISA has added two new entries to its Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation in the field. One involves a critical-severity OS command injection vulnerability in Arista Networks' VeloCloud Orchestrator (VCO), while the other targets a sensitive information exposure issue within Fortinet's FortiOS.

The Arista vulnerability carries a CVSS score of 10.0, indicating it can be exploited remotely without authentication to impact the confidentiality, integrity, and availability of the orchestrator and its managed data. The Fortinet flaw, rated as medium severity, allows attackers to bypass specific security patches if they have already achieved filesystem-level access through another vulnerability.

What happened

Arista VeloCloud Orchestrator OS Command Injection

A critical vulnerability in Arista's VeloCloud Orchestrator (VCO) on-prem allows remote attackers to access privileged internal functionality. This flaw, tracked as CVE-2026-16812, is an OS command injection issue that can impact the VCO host and any data it manages.

The vulnerability is reachable without credentials and does not require specific configurations to exploit; however, a successful attack requires network access to the VCO web interface. Because the orchestrator manages connected devices, a compromise of this platform may grant attackers access to VeloCloud Edge devices as well.

Fortinet FortiOS Information Exposure

CVE-2025-68686 describes an exposure of sensitive information within FortiOS SSL-VPN. This vulnerability allows a remote unauthenticated attacker to bypass a patch designed to prevent symbolic link persistency mechanisms used in post-exploit scenarios.

This flaw is not a standalone entry point for attackers; it can only be abused if a threat actor has already compromised the product via another vulnerability at the filesystem level to implement read-only access. Products that do not have SSL-VPN enabled are not impacted by this specific issue.

Affected products and fixed versions

Arista VeloCloud Orchestrator (VCO) On-Prem

The following versions are vulnerable:

  • VCO 5.2.x releases prior to 5.2.3.14
  • VCO 6.1.x releases prior to 6.1.3.4
  • VCO 6.4.x releases prior to 6.4.2.4
  • VCO 7.0.x releases prior to 7.0.0.1

Fixed versions include:

  • VCO 5.2.3.14 and later
  • VCO 6.1.3.4 and later
  • VCO 6.4.2.4 and later
  • VCO 7.0.0.1 and later

Fortinet FortiOS

The following versions are affected by CVE-2025-68686:

  • FortiOS 7.6.0 through 7.6.1
  • FortiOS 7.4.0 through 7.4.6
  • FortiOS 7.2 all versions
  • FortiOS 7.0 all versions
  • FortiOS 6.4 all versions

Detection opportunities

Operators managing Arista VCO should monitor web access logs for suspicious activity, specifically looking for:

  • Requests containing unusual URL-like path components or encoded characters.
  • High request rates targeting the web interface.
  • References to local or internal services within requests.

System administrators should also inspect backend application and system logs for:

  • Unexpected outbound HTTP or HTTPS activity originating from the VCO host.
  • Sensitive configuration changes not tied to known administrative workflows.
  • Unexpected command execution, file creation, or database exports on the host.

Why this matters for defenders

The Arista vulnerability represents a high-impact risk because it targets the control plane of the network. A successful exploit can lead to unauthorized access to managed device inventories, credentials, and certificates. If an orchestrator is compromised, the entire downstream infrastructure-including VeloCloud Edge devices-is at risk.

For Fortinet environments, the risk is tied to persistence. The vulnerability allows attackers who have already gained a foothold to bypass previous security fixes intended to disrupt their presence on the filesystem.

Defender guidance

Immediate Actions for Arista VCO:

  1. Upgrade: Apply the latest fixed release for your specific software train (e.g., 5.2.3.14, 6.1.3.4, etc.) immediately.
  2. Network Isolation: Restrict access to the VCO web interface so it is only reachable from trusted administrative networks.
  3. Incident Response: If a compromise is suspected, preserve all VCO web access logs, backend application logs, system logs, and database logs before performing remediation.

Actions for Fortinet FortiOS:

  1. Patching: Review your current FortiOS version against the affected list and apply updates to mitigate the information exposure risk.
  2. Virtual Patching: A virtual patch named FG-VD-60389.0day is available in FMWP db update 26.033.

Sources

  1. https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
  2. https://fortiguard.fortinet.com/psirt/FG-IR-25-934
  3. https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
  4. https://www.cve.org/CVERecord?id=CVE-2025-68686
  5. https://www.cve.org/CVERecord?id=CVE-2026-16812
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -