CISA adds FortiOS, Arista VeloCloud flaws to KEV
CISA added actively exploited Fortinet FortiOS and Arista VeloCloud Orchestrator vulnerabilities to its Known Exploited Vulnerabilities catalog, requiring federal remediation.
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation: CVE-2025-68686, an information disclosure flaw in Fortinet FortiOS, and CVE-2026-16812, an OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem. Both products are widely deployed in enterprise network infrastructure, making them attractive targets for threat actors seeking initial access or further compromise.
Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch agencies must prioritize remediation of KEV-listed vulnerabilities on internet-exposed assets, particularly those enabling full asset takeover, and verify whether systems were compromised prior to patching. While the directive is mandatory only for FCEB agencies, CISA recommends all organizations adopt similar risk-based patching practices for these two vulnerabilities given their confirmed in-the-wild exploitation.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free