INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Arista VeloCloud Orchestrator Exploit Vulnerability Found

| 2026-07-28 04:43 CRITICAL HIGH
Executive Summary AI-generated
The vulnerability, CVE-2026-16812, has been added to the Known Exploited Vulnerabilities (KEV) catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). This information disclosure vulnerability affects multiple versions of Fortinet's FortiOS operating system, exposing privileged internal functionality that was intended for trusted components only. The flaw allows specially crafted HTTP requests to bypass symbolic link protection, potentially compromising confidentiality, integrity, and availability of both the orchestrator and network data it manages. Organizations are advised to block affected IP addresses and check logs for signs of compromise as soon as possible.
Technical Mitigations AI-generated
* Implement a secure patching strategy for FortiOS and VeloCloud Orchestrator to prevent the persistence of malicious symbolic links, including: + Regularly updating and patching operating systems and applications + Using secure configuration options and monitoring system logs for signs of compromise + Limiting access to sensitive areas of the network and implementing role-based access control (RBAC) * Implement a robust security posture by: + Conducting regular vulnerability assessments and penetration testing + Establishing incident response plans and procedures + Providing ongoing training and awareness programs for employees * Monitor system logs, application performance, and user activity to detect signs of compromise or exploitation of the Arista VeloCloud Orchestrator command injection flaw. * Consider implementing a web application firewall (WAF) or intrusion detection/prevention system (IDPS) to block suspicious traffic patterns and prevent attacks.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-68686CVE-2025-68686 CVE-2026-16812CVE-2026-16812 CVE-2026-16723CVE-2026-16723
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎July 20, 2026
Threat actors exploited the Arista VeloCloud Orchestrator Command Injection flaw.
‎Jul 28, 2026
The attackers exploited a command injection flaw in Arista VeloCloud Orchestrator (VCO) to gain unauthorized access.
infrastructure 5.2
infrastructure 5.2.3
infrastructure 6.1
infrastructure 6.1.3
infrastructure 6.4
infrastructure 6.4.2
infrastructure 7.0
infrastructure 7.0.0
organisation VCO 5.2.x
organisation VCO 6.4.x
organisation IP
organisation VCO
organisation the VeloCloud Edge
organisation Arista
‎2026/07/28
Arista VeloCloud Orchestrator (VCO) and Fortinet FortiOS vulnerabilities were exploited in the wild.
organisation Unauthorized Actor Vulnerability
organisation VCO
organisation CVE-2026
organisation Known Exploited
infrastructure 5.2
infrastructure 5.2.3
infrastructure 6.1
infrastructure 6.1.3
infrastructure 6.4
infrastructure 6.4.2
infrastructure 7.0
infrastructure 7.0.0
organisation VeloCloud Orchestrator Hosted
organisation IP
organisation CVSS
organisation CVE-2025
organisation VeloCloud Orchestrator Command Injection Flaw
organisation VeloCloud Orchestrator
organisation Arista
organisation Fortinet
organisation SD-WAN
organisation VMware
organisation Hosted
organisation BleepingComputer
organisation VeloCloud Edge
organisation the Arista Technical Assistance Center
organisation Unexpected
organisation Suspicious
organisation EDR
‎July 30, 2026
Threat actors exploited a command injection flaw in Fortinet's FortiOS SSL-VPN to bypass the patch for CVE-2026-16812.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
organisation CVE-2026
organisation Fortinet FortiOS SSL-VPN
organisation CVSS
organisation Fortinet
organisation FortiOS SSL-VPN
organisation Fortinet FortiOS
‎Thursday, July 30, 2026
Threat actors exploited a command injection flaw in the Arista VeloCloud Orchestrator to gain unauthorized access.
attribution IP
‎August 10, 2026
Developers using versions 1.2.68 through 1.2.83 of Alibaba's Fastjson library are urged to update due to a command injection flaw that could allow remote code execution.
infrastructure 1.2.68
infrastructure 1.2.83
Tactical Metrics
Metrics
infrastructure
‎5.2
Software Version
Metrics
infrastructure
‎5.2.3
Software Version
Metrics
infrastructure
‎6.1
Software Version
Metrics
infrastructure
‎6.1.3
Software Version
Metrics
infrastructure
‎6.4
Software Version
Metrics
infrastructure
‎6.4.2
Software Version
Metrics
infrastructure
‎7.0
Software Version
Metrics
infrastructure
‎7.0.0
Software Version
Metrics
infrastructure
‎1.2.68
Software Version
Metrics
infrastructure
‎1.2.83
Software Version