Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

Arista, Fortinet and Cisco flaws listed

1 min read
12:09UTC

CISA catalogued CVE-2026-16812 in Arista's VeloCloud Orchestrator and CVE-2025-68686 in Fortinet FortiOS on 27 July, then CVE-2026-20316 in Cisco's firewall console on 29 July.

TechnologyAssessed
Key takeaway

All three newly catalogued flaws sit in network management planes, not in end-user software.

CISA added two flaws to its federal exploited-vulnerability catalogue on 27 July and a third on 29 July 1. Arista Networks supplied the first, an operating-system command injection in VeloCloud Orchestrator On-Prem, filed as CVE-2026-16812 and due for federal remediation by 30 July. Fortinet supplied the second, an exposure of sensitive information in FortiOS, filed as CVE-2025-68686 and due by 10 August. Cisco supplied the third, a hard-coded password in Secure Firewall Management Center, filed as CVE-2026-20316 and due by 1 August. A CVE identifier, short for Common Vulnerabilities and Exposures, is the industry's shared reference number for a specific flaw, and the catalogue lists only those CISA has confirmed attackers are already using.

The products themselves share a shape. VeloCloud Orchestrator manages wide-area network links across sites; Secure Firewall Management Center is the console from which Cisco firewall estates are configured; FortiOS runs the FortiGate firewalls that sit at organisational perimeters. None of the three is a workstation application. An intruder who reaches a network-management console does not need to move laterally afterwards, because the console already speaks to every device it administers. A listing date also marks confirmation rather than the onset of attacks: CrowdSec logged exploitation of Fortinet's FortiSandbox roughly a month before that flaw reached the catalogue .

A hard-coded password separates the Cisco entry from the other two. Such a credential is shipped inside the product and identical on every installation, so knowing it once is knowing it everywhere; there is no rotation an operator can perform and no configuration mistake to blame. That class of defect has no partial mitigation short of the vendor's fix or removal of the console from any network an attacker can reach.

Deep Analysis

In plain English

CISA added three more security flaws to its official list of vulnerabilities being actively exploited by hackers in the ten days after 24 July: a Cisco firewall-management flaw with a hard-coded password built into the software, an Arista networking flaw, and a Fortinet firewall issue. The Cisco flaw is notable because a hard-coded password isn't a bug you can configure your way around; the fix has to come from Cisco itself in a firmware update, which is part of why federal agencies were given just three days to act on it.

What could happen next?
  • Risk

    A hard-coded password is a design defect, not a configuration gap, so no interim mitigation exists short of a firmware update from Cisco.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

CISA· 3 Aug 2026
Read original
Causes and effects
This Event
Arista, Fortinet and Cisco flaws listed
All three flaws sit in the management plane of network equipment, the layer an intruder reaches for once perimeter access exists.
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.