Arista has issued a patch to address a serious command injection vulnerability in its on-premises VeloCloud Orchestrator (VCO). This flaw could allow attackers to execute arbitrary commands on affected systems, potentially leading to unauthorized access and control. Organizations using VeloCloud Orchestrator should prioritize applying this patch to safeguard their networks. The vulnerability has been confirmed to be exploited in the wild, which heightens the urgency for users to update their systems promptly. Failure to address this issue could expose sensitive data and disrupt operations for affected companies.
On July 27, 2026, federal cybersecurity officials issued an emergency alert regarding serious vulnerabilities found in Fortinet and Arista routers. These flaws are reportedly being exploited by attackers, raising concerns about the security of networks that rely on these devices. Organizations using affected Fortinet and Arista products are urged to implement the necessary patches to protect against potential breaches. This situation underscores the need for timely updates and vigilant monitoring of network devices, as attackers are actively seeking to exploit these weaknesses. Federal authorities are closely monitoring the situation and advising companies to prioritize these updates to safeguard their systems.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities associated with Arista VeloCloud Orchestrator and Fortinet's FortiOS to its Known Exploited Vulnerabilities catalog. The specific vulnerability for Arista is identified as CVE-2025-68686. This inclusion indicates that these flaws are being actively exploited, posing a significant risk to users of these products. Organizations using Arista's VeloCloud Orchestrator or Fortinet's FortiOS should take immediate action to address these vulnerabilities to safeguard their systems from potential attacks. The urgency of this update emphasizes the need for timely patching and monitoring of network security.
A serious vulnerability has been discovered in the Arista VeloCloud Orchestrator, affecting on-premises deployments. This flaw allows attackers to perform OS command injection, giving them unauthorized access to privileged internal functions. As a result, organizations using this orchestrator should be particularly vigilant, as the vulnerability is being actively exploited in the wild. The situation underscores the need for immediate attention to prevent potential breaches. Users of affected systems must act quickly to secure their environments against this exploit.
A serious security flaw has been discovered in the on-premises version of Arista's VeloCloud Orchestrator, identified as CVE-2026-16812, which carries a maximum CVSS score of 10.0. This vulnerability is a command injection issue that could allow attackers to execute arbitrary code on affected systems. As it is actively being exploited in the wild, organizations using this software need to be particularly vigilant. The flaw affects on-premises deployments of the VeloCloud Orchestrator, which is used for managing network services. The implications of this vulnerability are significant, as it could lead to unauthorized access and control over critical network functions if left unaddressed.
Arista has released a patch for a serious command injection vulnerability in its on-premises VeloCloud Orchestrator, which is currently being exploited by attackers. This vulnerability poses a significant risk to organizations using the VeloCloud Orchestrator, as it allows unauthorized command execution, potentially compromising network security. Users are urged to apply the patch immediately to safeguard their systems. The active exploitation of this zero-day vulnerability emphasizes the need for timely updates and monitoring of security practices within organizations. As attacks continue, companies must remain vigilant about their software and promptly address any security flaws.
The Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating that they are actively being exploited by attackers. The first vulnerability, CVE-2025-68686, affects Fortinet's FortiOS, allowing unauthorized access to sensitive information. The second, CVE-2026-16812, impacts Arista's VeloCloud Orchestrator, enabling command injection attacks on the on-premises operating system. These vulnerabilities pose serious risks, particularly to federal agencies, which are urged to prioritize their remediation under Binding Operational Directive 26-04. While the directive specifically targets federal civilian agencies, CISA recommends that all organizations adopt similar risk-based approaches to vulnerability management to protect against these threats.