CVE-2025-68686: Fortinet FortiOS
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
A client-ready brief for teams responsible for AI tools, vendors, and exposure. It turns the public record into exposure checks, source links, and calm language for internal notes, client updates, board packs, and weekly risk reviews.
The brief is organised by operational use: exploited items first, incidents second, then policy and model signals that can change advice, approved-tool lists, or risk posture.
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Check Point SmartConsole Improper Authentication Vulnerability
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
WordPress Core SQL Injection Vulnerability
We have identified an issue where S3 endpoints for keys with special characters will be broken. We are actively investigating the correct mitigation for this issue.
The degradation has been mitigated. We are monitoring to ensure stability.
We are currently investigating this issue.
We have applied the mitigation and are monitoring the recovery.
Anthropic announced that Claude Mythos Preview (claude-mythos-preview) will be retired on June 30, 2026. Users are advised to migrate to Claude Mythos 5 (claude-mythos-5) using the provided migration guide.
Google published pricing for the new Gemini 3.5 Flash model. Standard paid tier input is $1.50/1M tokens, output is $9.00/1M tokens. Batch pricing is $0.75/1M input and $4.50/1M output. Free tier usage contributes to product improvement.
The claude-opus-4-1-20250805 model state changed to Deprecated on June 5, 2026, with a tentative retirement date of August 5, 2026. Users must migrate before the retirement date to avoid disruption.
These prompts stop the brief from becoming noise. Each question is attached to a source-backed item in the current watch board.
Do we or any important client environments run Fortinet FortiOS, and is remediation tracked?
Do we or any important client environments run Arista VeloCloud Orchestrator, and is remediation tracked?
Do we or any important client environments run Check Point SmartConsole, and is remediation tracked?
Do we or any important client environments run Microsoft SharePoint, and is remediation tracked?
Do we or any important client environments run WordPress Core, and is remediation tracked?
Does this incident affect a provider, dependency, customer promise, or operating assumption we rely on?
The point is to help people inspect exposure. Do not imply impact until an environment, vendor, or control is actually in scope.
Check exposure before forwarding urgency to anyone else.
Record the vendor, product, owner, and remediation status for any affected environment.
Update AI tool advice where a vendor policy, data-use record, or public incident changes the operating picture.
Preserve the PAI source trail when turning this into an internal note, client brief, board update, or advisory.
You can repackage the wrapper. You cannot remove the evidence trail.
| Item | Date | Source | Open |
|---|---|---|---|
| CVE-2025-68686: Fortinet FortiOS | 27 July 2026 | CISA Known Exploited Vulnerabilities Catalog | Source trail |
| CVE-2026-16812: Arista VeloCloud Orchestrator | 27 July 2026 | CISA Known Exploited Vulnerabilities Catalog | Source trail |
| CVE-2026-16232: Check Point SmartConsole | 22 July 2026 | CISA Known Exploited Vulnerabilities Catalog | Source trail |
| CVE-2026-50522: Microsoft SharePoint | 22 July 2026 | CISA Known Exploited Vulnerabilities Catalog | Source trail |
| CVE-2026-60137: WordPress Core | 21 July 2026 | CISA Known Exploited Vulnerabilities Catalog | Source trail |
| Supabase: S3 endpoints for keys with special characters broken | 16 July 2026 | Production AI public record | Source trail |
| Disruption with some GitHub services | 16 July 2026 | Production AI public record | Source trail |
| Anthropic: Elevated errors for Claude Opus 4.7 | 16 July 2026 | Production AI public record | Source trail |
| OpenAI: Elevated Error Rates For SSO Login | 16 July 2026 | Production AI public record | Source trail |
| Anthropic: Claude Mythos Preview retirement announced for June 30, 2026 | 14 July 2026 | Production AI public record | Source trail |
| Google: Gemini 3.5 Flash model pricing published | 11 July 2026 | Production AI public record | Source trail |
| Anthropic: Claude Opus 4.1 deprecated, retirement August 5 2026 | 10 July 2026 | Production AI public record | Source trail |
The live AI watch is the source. The AI risk brief is the translation layer for operators, founders, security teams, consultants, service providers, and anyone who has to explain what changed without pretending exposure is proven.
Save a watch for vendors, tools, controls, vulnerabilities, or operating questions. The public record stays open. A saved watch tells us what matters to you - not a promise of a private alert feed.