THREAT SUMMARY
Category: Active Exploitation / Network Security / Network Orchestration / Information Exposure / Operating-System Command Injection
Affected Products: Fortinet FortiOS, Arista VeloCloud Orchestrator On-Prem
CVEs: CVE-2025-68686, CVE-2026-16812
Primary Risks: Sensitive Information Exposure, Unauthorized Command Execution, Network-Management Compromise, Credential Exposure, Security-Control Manipulation, Service Disruption, Persistent Access
Threat Status: Confirmed Active Exploitation
Affected Environment: Federal Agencies, Enterprise Networks, Critical Infrastructure, Organizations Operating Fortinet FortiOS or Arista VeloCloud Orchestrator On-Prem
Attack Vectors: Unauthorized Exposure of Sensitive Information, Operating-System Command Injection
CISA Action: Added to Known Exploited Vulnerabilities Catalog
The Cybersecurity and Infrastructure Security Agency has added two vulnerabilities affecting Fortinet FortiOS and Arista VeloCloud Orchestrator On-Prem to its Known Exploited Vulnerabilities Catalog after confirming evidence of active exploitation.
The vulnerabilities were added on July 27, 2026, and affect technologies responsible for network security and centralized infrastructure management.
CVE-2025-68686 can expose sensitive information from affected FortiOS systems to unauthorized actors. CVE-2026-16812 involves operating-system command injection against on-premises VeloCloud Orchestrator deployments.
Their inclusion in the KEV Catalog confirms that malicious cyber actors are using the vulnerabilities against operational systems. CISA has not identified the responsible threat actors, named affected organizations or stated that the two vulnerabilities are being used as part of the same campaign.
FortiOS and VeloCloud Orchestrator can hold trusted positions within enterprise infrastructure. Compromise of these systems could expose security information, administrative credentials, network configurations or connected resources. An attacker who gains access to an orchestration host could also interfere with the systems and services managed through that platform.
Vulnerability Details
CVE-2025-68686 — Fortinet FortiOS
Vulnerability: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2025-68686 is an information-exposure vulnerability affecting Fortinet FortiOS.
Successful exploitation could allow an unauthorized actor to obtain sensitive information from an affected deployment. The operational consequences would depend on the information exposed, the configuration of the system and its position within the organization’s network.
FortiOS deployments can support security, network-management and access-control functions. Information obtained from those systems could assist an attacker in identifying protected resources, understanding network configurations, locating administrative services or preparing additional intrusion activity.
The vulnerability does not need to provide immediate control of a FortiOS device to create a serious threat. Exposed information can support credential attacks, network reconnaissance, exploitation of connected systems or attempts to evade existing defensive controls.
CISA has confirmed active exploitation but has not publicly disclosed the complete intrusion sequence, indicators of compromise, targeted organizations or identities of the malicious actors involved.
Organizations should identify affected FortiOS deployments, determine which systems are accessible from untrusted networks and apply available remediation according to CISA’s KEV requirements.
Security teams should also examine affected systems for signs of unauthorized access or information retrieval that may have occurred before remediation.
CVE-2026-16812 — Arista VeloCloud Orchestrator On-Prem
Vulnerability: Operating-System Command Injection
CVE-2026-16812 is an operating-system command-injection vulnerability affecting Arista VeloCloud Orchestrator On-Prem.
Successful exploitation could allow attacker-controlled commands to reach the operating system supporting the affected orchestrator. This creates a potential path to compromise the host and interfere with its data, services or administrative functions.
An on-premises orchestrator can provide centralized visibility and management across connected network infrastructure. Compromise of that system could create risks extending beyond the original host, depending on its privileges, stored credentials, administrative connections and access to managed environments.
Potential consequences include unauthorized configuration changes, credential theft, malicious account creation, service interruption, security-control manipulation, malware deployment and movement into connected systems.
CISA has confirmed that the vulnerability is being actively exploited. The agency has not publicly identified the threat actors, affected organizations, exploitation volume or complete technical method being used against vulnerable systems.
Organizations operating VeloCloud Orchestrator On-Prem should locate every affected deployment, remove unnecessary public exposure, apply available remediation and inspect the underlying host for evidence of compromise.
Operational Impact
Organizations operating affected systems could face:
- Sensitive information exposure
- Unauthorized access to network-security data
- Compromise of network-management infrastructure
- Operating-system command execution
- Orchestrator host compromise
- Unauthorized configuration changes
- Credential or administrative-secret exposure
- Loss of system confidentiality
- Loss of system integrity
- Service disruption
- Network-management interruption
- Malware deployment
- Creation of unauthorized accounts
- Lateral movement across enterprise networks
- Persistent attacker access
- Data theft
- Security-control manipulation
- Reduced visibility into managed infrastructure
- Business and operational disruption
The extent of the damage would depend on the affected product, its network exposure, the privileges assigned to the compromised service and the systems connected to it.
Federal Response
CISA added CVE-2025-68686 and CVE-2026-16812 to the Known Exploited Vulnerabilities Catalog under Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk.
BOD 26-04 establishes vulnerability-management requirements for Federal Civilian Executive Branch agencies. The directive requires federal agencies to prioritize high-risk KEV vulnerabilities affecting publicly exposed assets when successful exploitation can provide total control of the affected system.
The directive also establishes expectations for determining whether malicious actors compromised a system before security updates or mitigations were applied.
Federal agencies operating affected FortiOS or VeloCloud Orchestrator systems must identify vulnerable assets, evaluate their public exposure and operational importance, apply required remediation and complete compromise assessments when required by CISA.
Lower-risk vulnerabilities may receive deferred treatment under the directive, allowing agencies to direct resources toward actively exploited weaknesses presenting the greatest immediate threat.
BOD 26-04 applies specifically to Federal Civilian Executive Branch agencies. CISA encourages private companies, critical infrastructure operators, healthcare organizations, educational institutions, financial organizations, state governments, local governments and technology providers to adopt the same risk-based vulnerability-management approach.
KEV Catalog Continues to Expand
CISA continues adding vulnerabilities to the Known Exploited Vulnerabilities Catalog as evidence of active exploitation becomes available.
A vulnerability must have an assigned CVE identifier, reliable evidence of exploitation and clear mitigation guidance before it can qualify for inclusion.
Government agencies, security researchers, software providers and cybersecurity professionals may submit vulnerabilities for consideration through CISA’s KEV nomination process.
Defensive Guidance
Organizations operating affected systems should:
- Identify every Fortinet FortiOS deployment within the organization.
- Identify every Arista VeloCloud Orchestrator On-Prem deployment.
- Determine which affected systems are exposed to the internet or other untrusted networks.
- Apply available security updates and CISA-required mitigations.
- Remove unnecessary public access to management and orchestration interfaces.
- Restrict administrative access to trusted networks and authorized personnel.
- Review affected systems for evidence of exploitation before and after remediation.
- Examine administrative records for unfamiliar logins, sessions and configuration changes.
- Inspect orchestrator hosts for unexpected commands, processes, files, services and accounts.
- Review FortiOS systems for unauthorized access or suspicious information retrieval.
- Audit credentials and administrative secrets available to affected systems.
- Rotate credentials if unauthorized access is detected or suspected.
- Verify that routing rules, security policies and network configurations remain intact.
- Search connected systems for signs of lateral movement.
- Isolate affected assets when immediate remediation cannot be completed.
- Discontinue use of vulnerable products if effective mitigation is unavailable.
- Preserve system records and other relevant evidence for forensic examination.
- Continue monitoring after remediation for persistent or delayed attacker activity.
Forecast — 30 Days
- Accelerated exploitation attempts against organizations that delay remediation.
- Increased targeting of publicly accessible network-management interfaces.
- Additional attempts to obtain security configurations, credentials and administrative information from vulnerable FortiOS deployments.
- Continued command-injection activity against affected on-premises orchestrators.
- Increased development or modification of automated exploitation tools.
- Elevated incident-response activity involving network-security and orchestration infrastructure.
- Accelerated remediation across federal agencies and critical infrastructure environments.
- Continued additions to CISA’s KEV Catalog as new evidence of active exploitation is confirmed.
TRJ Verdict
The addition of CVE-2025-68686 and CVE-2026-16812 confirms that malicious cyber actors are actively targeting technologies positioned within important areas of network-security and management infrastructure.
Organizations should treat this KEV update as an immediate security event. Applying available remediation is only one part of the required response.
Confirmed active exploitation means the threat is already operational. Delayed action gives malicious actors additional time to identify and compromise systems that remain vulnerable.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



