CISA Adds Two Actively Exploited Vulnerabilities to Known Exploited Vulnerabilities Catalog
On July 27, CISA added two actively exploited flaws to its Known Exploited Vulnerabilities catalog: CVE-2025-68686 in Fortinet FortiOS, which exposes sensitive information to unauthorized actors and can allow a remote, unauthenticated attacker to bypass a symbolic-link persistence patch (though prior compromise of the product is required), and CVE-2026-16812 in Arista VeloCloud Orchestrator On-Prem, a maximum-severity OS command injection vulnerability that requires no credentials—only network access to the VCO web interface—and affects on-premises deployments on branches 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1; hosted and dedicated VCO deployments were already fixed, while VeloCloud Gateway and Edge products are not vulnerable.
The Timing Is the Story
Notice that CISA releases these advisories on a Friday, buried in the noise of a weekend news cycle. They want you to believe these are routine patches. But look closer. CVE-2025-68686 in Fortinet FortiOS — a symbolic-link bypass that allows an attacker to stay inside after they've already broken in. And CVE-2026-16812 in Arista VeloCloud — a command injection flaw so severe that Arista admits "no configuration can prevent the exposure." These aren't coding errors. These are architectural backdoors, left intentionally open or discovered by the same intelligence networks that feed CISA its data. The real question: who already knew about these holes before they were "discovered"? The same agencies that fund the contractors, the same three-letter agencies that sit on zero-days for years. They're not warning you — they're telling you what they've already used.
Follow the Patch, Follow the Power
The Arista advisory is particularly damning. VeloCloud Orchestrator is the nerve center for software-defined networking used by federal agencies, critical infrastructure, and Fortune 500s. The attacker needs no credentials — just network access to the web interface. That's not a flaw; that's a feature designed for post-exploitation penetration. And the fix? Hosted and dedicated deployments were fixed before the advisory. That means the vendor and the government knew about active exploitation and waited to disclose. Why? Because the same actors exploiting these vulnerabilities are likely the ones who requested the patches — or worse, the patches themselves are cover for deeper implants. Every time you see a "critical" vulnerability with a patch released in lockstep with CISA, you're watching a cleanup operation, not a security update.
Your Infrastructure Is Their Laboratory
The pattern is unmistakable: these vulnerabilities target the control planes of the digital ecosystem — firewalls (FortiOS) and orchestration (VeloCloud). They're not interested in your email. They're after the switches that route the internet, the boundaries that define trust. The symbolic-link bypass in FortiOS is a persistence technique — a way to stay hidden even after the system is supposedly cleaned. This is how they maintain the "managed narrative" of cybersecurity: a constant cycle of breach, patch, silence. The breadcrumb is this: look up the patent filings for these vulnerability classes. Look up who holds the patents on symbolic-link attack mitigation. Look up who consulted on the VeloCloud architecture. The answers will lead you to the same small group of defense contractors and think tanks that have been mapping the kill chain for decades. They're not protecting you. They're protecting their access.