CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog on 27 July 2026: CVE-2026-16812, an OS command injection flaw in Arista VeloCloud Orchestrator On-Prem, due 30 July, and CVE-2025-68686, an information exposure flaw in Fortinet FortiOS, due 10 August. Both entries record ransomware campaign use as Unknown. That field describes the evidence CISA holds today, not the risk the flaws carry: one hands a remote attacker the SD-WAN management plane, the other defeats a fix for post-exploitation persistence on a firewall.
Juan Ricardo Palacio
Co-Founder and CEO for the Americas, HelpRansomware
Electronic engineer and Co-Founder of HelpRansomware, with 25+ years in cybersecurity, digital forensics and ransomware incident response.
Two new entries in the CISA catalog. Two deadlines, eleven days apart. And in the ransomware column of both, the same word: Unknown.
On 27 July 2026 CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog, the list of flaws it has confirmed are being exploited in the wild. The first, CVE-2026-16812, is an OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem, the self-hosted console used to manage SD-WAN networks. CISA gave United States federal civilian agencies until 30 July to remediate it, three days. The second, CVE-2025-68686, is an exposure of sensitive information in Fortinet FortiOS, with a deadline of 10 August. Neither entry is tied to a ransomware campaign: the catalog field knownRansomwareCampaignUse reads Unknown for both. That single word is the reason this pair is worth reading closely, because it is routinely mistaken for a risk rating.
A patched appliance is not a cleared appliance
The FortiOS entry is not about getting in. CISA describes it as a bypass of the patch built for the symbolic link persistency mechanism observed in some post-exploit cases, reachable through crafted HTTP requests, and notes that an attacker would first need to have compromised the product through another vulnerability, at filesystem level. It is a flaw about staying in.
What CISA published
The facts below come from the KEV catalog entries dated 27 July 2026 and from the vendor advisories those entries reference.
- CVE-2026-16812 affects Arista VeloCloud Orchestrator On-Prem. CISA describes an OS command injection that may allow a remote attacker to access privileged internal functionality and impact the VCO host, compromising the confidentiality, integrity and availability of the orchestrator and the data it manages.
- CVE-2025-68686 affects Fortinet FortiOS. CISA describes an exposure of sensitive information to an unauthorized actor that bypasses the patch developed for the symbolic link persistency mechanism, via crafted HTTP requests.
- Both were added on 27 July 2026, in catalog version 2026.07.27, which holds 1,655 entries in total.
- The required action for both is tied to Binding Operational Directive 26-04, on prioritising security updates based on risk, with due dates of 30 July 2026 and 10 August 2026 respectively.
- The catalog records knownRansomwareCampaignUse as Unknown for both entries.
The two entries in numbers
Dates, product names, descriptions and due dates come directly from the CISA Known Exploited Vulnerabilities catalog entries of 27 July 2026. The CVSS score of 10.0 and the fixed build numbers come from reporting published on 27 and 28 July by BleepingComputer, The Hacker News and The Register, not from the catalog itself, and are given here as reported.
What the reporting adds to the catalog entry
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks.
How the week unfolded
The sequence below is short, and that is the point. Three days separate a public fix from a federal deadline. Read against how a ransomware attack usually unfolds, that interval is the part defenders actually control.
The two entries side by side
Two flaws, two very different clocks
CISA KEV catalog entries of 27 July 2026. CVSS score as reported by BleepingComputer, The Hacker News and The Register.
What the entries say, and what readers add
Each row pairs an assumption we hear during exposure reviews with what these two catalog entries actually state.
| Common assumption | What the KEV entries state | Why it matters for readiness |
|---|---|---|
| Ransomware use Unknown means low priority | Unknown means CISA has no confirmed ransomware campaign tied to the flaw today | It records current evidence and is updated when evidence arrives. It is not a rating and not a forecast |
| The orchestrator is an internal tool | The flaw may allow a remote attacker to reach privileged internal functionality and impact the VCO host | The console that manages an SD-WAN is network-wide reach, which is the position extortion operations are built from |
| Applying the update closes the case | The FortiOS entry describes a bypass of the fix for a persistence mechanism seen after exploitation | A device can report a current version and still be carrying an attacker foothold |
What goes wrong when Unknown is read as safe
The failure modes below are the ones that surface after the fact, in environments where a catalog entry was triaged on the wrong field.
- â›” Reading Unknown in the ransomware column as not relevant, and deprioritising a flaw that CISA has already confirmed is being exploited.
- â›” Patching the VeloCloud Orchestrator but leaving its web interface reachable from the internet, so the next flaw in the same component is exploitable on the day it is published.
- â›” Treating a three-day federal deadline as a public sector formality rather than as CISA’s own signal of how fast the flaw is being used.
- â›” Applying the FortiOS update without hunting for the filesystem persistence the fix exists to defeat, so a current appliance keeps serving the attacker.
- â›” Having no inventory of which VeloCloud Orchestrator deployments are self-hosted, so nobody can answer whether the fixed builds are actually installed.
The pattern behind edge device entries
CISA ties the required action for both flaws to Binding Operational Directive 26-04, whose stated purpose is prioritising security updates based on risk. Directives of that kind exist because the interval between a published fix for an internet-reachable appliance and its use in intrusions has become short enough to make ordinary patch cycles ineffective. Nothing in either catalog entry names an actor or a campaign, and this article does not either. What both entries do state is that exploitation is already confirmed.
What to do this week
Each item maps to something stated in the two catalog entries or in the advisories they reference. None of it depends on knowing who is exploiting the flaws, which is exactly why it also holds as baseline work for preventing a ransomware attack.
- ✅ Inventory every self-hosted VeloCloud Orchestrator instance and confirm it runs a fixed build. Reporting puts the fixed versions at 5.2.3.14, 6.1.3.4 and 6.4.2.4 and later, and notes that hosted and dedicated deployments were patched before the advisory was published.
- ✅ Take the VCO web interface off the open internet, behind a VPN or an address allowlist. Reporting states the flaw needs only network access to that interface, with no tenant or operator credentials.
- ✅ Apply the Fortinet fix referenced by the catalog entry, FG-IR-25-934, on every affected device, then verify filesystem state rather than the version string alone.
- ✅ Use the KEV due dates as internal service levels: 30 July 2026 for CVE-2026-16812 and 10 August 2026 for CVE-2025-68686, whether or not the directive applies to you.
- ✅ Preserve orchestrator and firewall logs before rebuilding anything. If a compromise is confirmed later, they are the only record of what the attacker could reach.
- ✅ Re-check both catalog entries after remediation. The ransomware campaign field is updated when CISA obtains evidence, so today’s Unknown is not a permanent answer.
Exposure is the variable you control
Neither entry names a ransomware operator, and neither may ever do so. Both describe conditions that make an intrusion cheaper: a management console reachable from the internet, and a persistence mechanism whose fix can be bypassed. Closing that exposure is ordinary work with a published deadline, and it costs a fraction of recovering encrypted files once the same access has been used for something worse.
Sources
- CISA, Known Exploited Vulnerabilities Catalog, entries added 27 July 2026
- CISA, CISA Adds Two Known Exploited Vulnerabilities to Catalog, 27 July 2026
- Arista, Security Advisory 0144, VeloCloud Orchestrator On-Prem
- Fortinet PSIRT, FG-IR-25-934
- BleepingComputer, Arista patches VeloCloud Orchestrator zero-day exploited in attacks
- The Hacker News, Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
Juan Ricardo Palacio
Co-Founder and CEO for the Americas, HelpRansomware
Juan Ricardo Palacio is an electronic engineer, entrepreneur, and specialist in telecommunications, cybersecurity, and digital forensics, with more than 25 years of professional experience. As Co-Founder of HelpRansomware, he works across cyber resilience, ransomware incident response, data recovery, cryptography, and reverse engineering, supporting companies and organizations through high-impact cyber incidents.
📰 Featured and quoted in Forbes Georgia, Business Insider Africa, LA Weekly, and Il Sole 24 Ore.
📅 Last updated: 28 July 2026



