CISA added two flaws to its federal exploited-vulnerability catalogue on 27 July and a third on 29 July 1. Arista Networks supplied the first, an operating-system command injection in VeloCloud Orchestrator On-Prem, filed as CVE-2026-16812 and due for federal remediation by 30 July. Fortinet supplied the second, an exposure of sensitive information in FortiOS, filed as CVE-2025-68686 and due by 10 August. Cisco supplied the third, a hard-coded password in Secure Firewall Management Center, filed as CVE-2026-20316 and due by 1 August. A CVE identifier, short for Common Vulnerabilities and Exposures, is the industry's shared reference number for a specific flaw, and the catalogue lists only those CISA has confirmed attackers are already using.
The products themselves share a shape. VeloCloud Orchestrator manages wide-area network links across sites; Secure Firewall Management Center is the console from which Cisco firewall estates are configured; FortiOS runs the FortiGate firewalls that sit at organisational perimeters. None of the three is a workstation application. An intruder who reaches a network-management console does not need to move laterally afterwards, because the console already speaks to every device it administers. A listing date also marks confirmation rather than the onset of attacks: CrowdSec logged exploitation of Fortinet's FortiSandbox roughly a month before that flaw reached the catalogue .
A hard-coded password separates the Cisco entry from the other two. Such a credential is shipped inside the product and identical on every installation, so knowing it once is knowing it everywhere; there is no rotation an operator can perform and no configuration mistake to blame. That class of defect has no partial mitigation short of the vendor's fix or removal of the console from any network an attacker can reach.
