CISA Adds Two Known Exploited Vulnerabilities to Catalog: Fortinet FortiOS Information Disclosure (CVE-2025-68686) and Arista VeloCloud Orchestrator OS Command Injection (CVE-2026-16812) — Threadlinqs Intelligence
As of 2026-07-28, CISA Adds Two Known Exploited Vulnerabilities to Catalog: Fortinet FortiOS Information Disclosure (CVE-2025-68686) and Arista VeloCloud Orchestrator OS Command Injection (CVE-2026-16812) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 33 indicators of compromise.
Threat ID: TL-2026-1725 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-07-28 · revalidated 1× · latest source
CISA added two actively-exploited vulnerabilities to its KEV catalog on 2026-07-27: CVE-2025-68686, a FortiOS flaw letting a remote unauthenticated attacker bypass Fortinet's SSL-VPN
This threat bundles two independent CISA KEV additions announced the same day. CVE-2025-68686 (CWE-200, CVSS 3.1 base 5.9, AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) affects Fortinet FortiOS 6.4/7.0/7.2 (all versions) and 7.4.0-7.4.6/7.6.0-7.6.1. It is a bypass of the patch Fortinet shipped (versions 7.6.2, 7.4.7, 7.2.11, 7.0.17, 6.4.16) to remove a symlink-based persistence technique first disclosed in April 2025: threat actors who had achieved remote code execution via CVE-2022-42475, CVE-2023-27997, or CVE-2024-21762 created a symbolic link connecting the user and root filesystems inside the directory used to serve SSL-VPN UI language files, giving them continued read-only access to device configuration even after the initial RCE vulnerability was patched. Fortinet CISO Carl Windsor confirmed the symlink was placed strategically in the user filesystem to evade detection and could survive even after the original RCE vulnerabilities were remediated. Shadowserver identified 16,620 internet-exposed FortiGate devices still carrying the malicious symlink as of 2025-04-15, distributed globally across Asia (7,886), Europe (3,766), and North America (3,217); CERT-FR documented related compromises dating back to early 2023. CVE-2025-68686 lets an unauthenticated attacker send crafted HTTP requests to bypass Fortinet's symlink-removal fix on a device that was previously compromised at the filesystem level — it cannot be exploited standalone, requires SSL-VPN to be enabled, and the vulnerability itself is information-disclosure only (no confirmed integrity/availability impact per NVD's AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N vector). Fortinet credits researcher Peter Gabaldon (ITRESIT) and published PSIRT advisory FG-IR-25-934 (initial: 2026-02-10/13, updated 2026-03-12), alongside FortiGuard FMWP virtual-patch signature FG-VD-60389.0day (DB update 26.033).
CVE-2026-16812 (CWE-78, CVSS 3.1 and 4.0 both 10.0 CRITICAL, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) affects Arista VeloCloud Orchestrator (VCO) On-Prem 5.2.0-<5.2.3.14, 6.1.0-<6.1.3.4, 6.4.0-<6.4.2.4, and 7.0.0-<7.0.0.1. Per Arista Security Advisory 0144 (published 2026-07-27, Bug ID 1901675), "VCO is exposed by default. There is no configuration that can prevent the exposure" and "VCO tenant or operator credentials are not required for this exposure" — an attacker who reaches the VCO web interface can access administrative/maintenance functionality that "was intended to be for internal use only and is not intended to be remotely accessible," injecting OS commands and gaining privileged access to the underlying orchestrator host. This fully compromises confidentiality, integrity, and availability of the SD-WAN orchestration platform and can expose "VCO database contents, configuration data, device inventory, credentials, certificates, or key material." Arista's own remediation guidance directs operators to hunt for "unexpected outbound HTTP or HTTPS activity originating from the VCO host," "sensitive configuration changes that do not correspond to administrator activity," and "unexpected command execution, file creation, database export, or archive artifacts" — all consistent with post-compromise C2 beaconing, configuration exfiltration, and credential/key-material theft. Arista identified three IP addresses observed conducting attacks against the flaw: 8.19.75.217, 206.72.242.124, and 206.72.242.162; a BeaconBeagle infrastructure-correlation check against all three returned no existing beacon/C2 record (no historical match at query time). Only VCO On-Prem was affected — Hosted, Dedicated, Gateway, and Edge VeloCloud products, plus all EOS-based switches and CloudVision, were unaffected or already patched by Arista before the advisory's public release. Arista states the issue was discovered externally and is known to be actively exploited. Fixed releases are 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1.
CISA added both CVEs to the KEV catalog on 2026-07-27 under Binding Operational Directive 26-04
Weaknesses (CWE)
CWE-200, CWE-78
Target sectors: government administration, enterprise-networking
Detections & IOCs
As of 2026-08-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 33 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2025-68686, CVE-2026-16812, T1595, T1190, T1059, T1601, T1068, T1211, T1014, T1552, T1082, T1005