Independent Reviews
Back to VPN Security News
CybersecurityPublished 28 Jul 20266 min read3 sources

CISA Adds Fortinet and Arista Flaws to KEV: What Network-Edge Users Should Do

CISA says two actively exploited flaws affecting Fortinet FortiOS and Arista VeloCloud Orchestrator On-Prem have joined its Known Exploited Vulnerabilities catalog.

Quick takeaways

  • CISA added CVE-2025-68686 in Fortinet FortiOS and CVE-2026-16812 in Arista VeloCloud Orchestrator On-Prem to its KEV catalog after evidence of active exploitation.
  • Arista describes the VeloCloud Orchestrator issue as a critical unauthenticated OS command injection flaw affecting on-prem deployments before fixed releases.
  • A consumer VPN protects your traffic on untrusted networks; it does not patch, harden or monitor a vulnerable VPN, firewall or SD-WAN management appliance.

What happened?

CISA added two flaws to its Known Exploited Vulnerabilities catalog on 27 July 2026: CVE-2025-68686, described as a Fortinet FortiOS exposure of sensitive information vulnerability, and CVE-2026-16812, described as an Arista VeloCloud Orchestrator On-Prem OS command injection vulnerability. CISA says the additions are based on evidence of active exploitation.

Arista's own advisory says CVE-2026-16812 affects VeloCloud Orchestrator On-Prem and may allow a remote unauthenticated attacker to access privileged internal functionality, affecting the confidentiality, integrity and availability of the orchestrator and data it manages. Arista rates the issue critical with CVSS 10.0 scores and lists fixed releases for VCO 5.2.x, 6.1.x, 6.4.x and 7.0.x. Fortinet's PSIRT advisory says the FortiOS SSL-VPN issue can allow a remote unauthenticated attacker to bypass a patch for a symbolic-link persistence mechanism, but notes the attacker would first need filesystem-level compromise through another vulnerability.

Why it matters

VPN Rocks readers usually think about VPNs as apps on phones, laptops and routers. This warning is about the other side of the equation: exposed network-edge infrastructure used by businesses, service providers and administrators. When firewall, VPN or SD-WAN management systems are vulnerable, attackers may be able to persist, steal data, alter configurations or pivot deeper into the network.

The consumer lesson is not that VPNs are bad. It is that a VPN product is only as trustworthy as the software, configuration, update process and operator behind it. For remote workers, small businesses and households using advanced gateways, appliance security matters just as much as choosing a privacy-friendly VPN provider.

What you can do now

If you administer FortiOS SSL-VPN or Arista VeloCloud Orchestrator On-Prem, check the vendor advisories immediately, confirm whether the affected versions are present, apply the listed fixed releases or migrations, and restrict web management interfaces to trusted administrative networks. Because CISA added the flaws to KEV after active exploitation evidence, patching alone may not be enough: review logs, access paths, administrator accounts and unusual configuration changes for signs of earlier compromise.

If you are an employee or customer rather than an administrator, ask your IT provider whether internet-facing VPN, firewall and SD-WAN systems are tracked against CISA KEV entries. For small businesses, this is a useful prompt to inventory remote-access products, turn off unused SSL-VPN features, remove unsupported releases and require phishing-resistant MFA for administrators.

Where a VPN helps — and where it does not

A reputable VPN app can still help protect your traffic on hotel Wi-Fi, public networks and untrusted access points. It can reduce what local network operators see and, in some configurations, avoid local DNS tampering.

A VPN does not fix a vulnerable VPN appliance. It does not patch FortiOS or VeloCloud, does not remove a persistence mechanism left after a prior breach and does not prove that a provider's infrastructure is hardened. The fix for this class of problem is asset inventory, vendor patching, exposure reduction, log review and incident response — not buying a second privacy app.

VPN Rocks view

This is a useful trust check for VPN and remote-access claims. Network-edge tools sit in privileged positions, so maintenance quality matters. The safest framing for ordinary users is simple: use a VPN for network privacy, but judge any VPN or remote-access product by its update record, transparency and security posture.

For businesses, CISA KEV should be treated as an operational to-do list rather than a news feed. If a remote-access product is listed and exposed, the clock has already started.

Sources and further reading

VPN Rocks adds plain-English analysis and practical advice. Source links are included so readers can check the underlying guidance directly.

Useful next steps