Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

Arista, Fortinet and Cisco flaws listed

1 min read
16:08UTC

CISA catalogued CVE-2026-16812 in Arista's VeloCloud Orchestrator and CVE-2025-68686 in Fortinet FortiOS on 27 July, then CVE-2026-20316 in Cisco's firewall console on 29 July.

TechnologyAssessed
Key takeaway

All three newly catalogued flaws sit in network management planes, not in end-user software.

CISA added two flaws to its federal exploited-vulnerability catalogue on 27 July and a third on 29 July 1. Arista Networks supplied the first, an operating-system command injection in VeloCloud Orchestrator On-Prem, filed as CVE-2026-16812 and due for federal remediation by 30 July. Fortinet supplied the second, an exposure of sensitive information in FortiOS, filed as CVE-2025-68686 and due by 10 August. Cisco supplied the third, a hard-coded password in Secure Firewall Management Center, filed as CVE-2026-20316 and due by 1 August. A CVE identifier, short for Common Vulnerabilities and Exposures, is the industry's shared reference number for a specific flaw, and the catalogue lists only those CISA has confirmed attackers are already using.

The products themselves share a shape. VeloCloud Orchestrator manages wide-area network links across sites; Secure Firewall Management Center is the console from which Cisco firewall estates are configured; FortiOS runs the FortiGate firewalls that sit at organisational perimeters. None of the three is a workstation application. An intruder who reaches a network-management console does not need to move laterally afterwards, because the console already speaks to every device it administers. A listing date also marks confirmation rather than the onset of attacks: CrowdSec logged exploitation of Fortinet's FortiSandbox roughly a month before that flaw reached the catalogue .

A hard-coded password separates the Cisco entry from the other two. Such a credential is shipped inside the product and identical on every installation, so knowing it once is knowing it everywhere; there is no rotation an operator can perform and no configuration mistake to blame. That class of defect has no partial mitigation short of the vendor's fix or removal of the console from any network an attacker can reach.

Deep Analysis

In plain English

CISA added three more security flaws to its official list of vulnerabilities being actively exploited by hackers in the ten days after 24 July: a Cisco firewall-management flaw with a hard-coded password built into the software, an Arista networking flaw, and a Fortinet firewall issue. The Cisco flaw is notable because a hard-coded password isn't a bug you can configure your way around; the fix has to come from Cisco itself in a firmware update, which is part of why federal agencies were given just three days to act on it.

What could happen next?
  • Risk

    A hard-coded password is a design defect, not a configuration gap, so no interim mitigation exists short of a firmware update from Cisco.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

CISA· 3 Aug 2026
Read original
Causes and effects
This Event
Arista, Fortinet and Cisco flaws listed
All three flaws sit in the management plane of network equipment, the layer an intruder reaches for once perimeter access exists.
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.