# CISA adds FortiOS, Arista VeloCloud flaws to KEV

Published: 2026-07-27 · Severity: high · Sectors: government-national, technology, telecommunications
Canonical: https://vorant.io/reports/60e683fd-4e19-511a-bd67-4fa425a474f2/cisa-adds-fortios-arista-velocloud-flaws-to-kev

> CISA added actively exploited Fortinet FortiOS and Arista VeloCloud Orchestrator vulnerabilities to its Known Exploited Vulnerabilities catalog, requiring federal remediation.

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation: CVE-2025-68686, an information disclosure flaw in Fortinet FortiOS, and CVE-2026-16812, an OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem. Both products are widely deployed in enterprise network infrastructure, making them attractive targets for threat actors seeking initial access or further compromise.

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch agencies must prioritize remediation of KEV-listed vulnerabilities on internet-exposed assets, particularly those enabling full asset takeover, and verify whether systems were compromised prior to patching. While the directive is mandatory only for FCEB agencies, CISA recommends all organizations adopt similar risk-based patching practices for these two vulnerabilities given their confirmed in-the-wild exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2025-68686, CVE-2026-16812

Source reporting: https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/60e683fd-4e19-511a-bd67-4fa425a474f2/cisa-adds-fortios-arista-velocloud-flaws-to-kev.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
