A CVSS 10 in the SD-WAN Controller and a Symlink Bypass in FortiOS: CISA Gives Agencies Three Days
CISA added two actively exploited flaws to the KEV catalog on July 27. CVE-2026-16812 is an unauthenticated command injection in Arista VeloCloud Orchestrator scoring a perfect 10.