Answer Brief
CISA has added CVE-2025-68686 (Fortinet FortiOS information exposure) and CVE-2026-16812 (Arista VeloCloud Orchestrator command injection) to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation, reinforcing BOD 26-04 requirements for federal agencies and urging all organizations to prioritize patching.
Signal Timeline
A quick visual path for analysts before reading the full brief.
- 1
CISA adds CVE-2025-68686 and CVE-2026-16812 to Known Exploited Vulnerabilities Catalog
- 2
Current runtime date; vulnerability additions treated as current/historical
Executive Summary: CISA has added CVE-2025-68686 (Fortinet FortiOS information exposure) and CVE-2026-16812 (Arista VeloCloud Orchestrator command injection) to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation, reinforcing BOD 26-04 requirements for federal agencies and urging all organizations to prioritize patching.
Why It Matters
CISA's addition of CVE-2025-68686 and CVE-2026-16812 to the Known Exploited Vulnerabilities Catalog reflects ongoing threats targeting widely deployed network and cloud infrastructure technologies. CVE-2025-68686 involves an information exposure flaw in Fortinet FortiOS that could allow unauthorized actors to access sensitive data, a vulnerability type frequently exploited in initial access or reconnaissance phases of attacks. CVE-2026-16812 describes an OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem, which, if exploited, could enable attackers to execute arbitrary commands on the underlying system, potentially leading to full control of cloud management infrastructure. Both vulnerabilities are explicitly cited by CISA as being actively exploited in the wild, meeting the strict criteria for KEV Catalog inclusion: a valid CVE ID, reliable evidence of exploitation, and clear mitigation guidance available through vendor advisories. The timing of this alert underscores the persistent risk posed by unpatched vulnerabilities in perimeter and management systems, which remain high-value targets for threat actors seeking to establish footholds in enterprise environments. Fortinet FortiOS is widely used in enterprise firewalls and VPN gateways, making it a common target for exploitation. Similarly, Arista VeloCloud Orchestrator plays a critical role in managing SD-WAN and cloud network infrastructure, meaning a compromise could have broad implications for network visibility, traffic control, and segmentation. The inclusion of these CVEs in the KEV Catalog serves as a prioritization signal for vulnerability management programs, especially given the exploitation context. BOD 26-04 provides the operational framework that elevates the importance of the KEV Catalog beyond a simple list. For Federal Civilian Executive Branch agencies, the directive mandates specific actions: prioritizing remediation of KEV-listed vulnerabilities on internet-accessible systems, verifying whether compromise occurred prior to patch application, and applying a risk-based approach that defers immediate action on lower-risk issues. While the directive applies only to FCEB agencies, CISA explicitly states that it encourages all organizations—including private sector, state, local, tribal, and territorial entities—to adopt similar practices. This reflects a broader intent to elevate the KEV Catalog as a de facto standard for effective vulnerability prioritization across critical infrastructure and enterprise sectors. For security and operations teams globally, the immediate implication is to review asset inventories for exposure to Fortinet FortiOS and Arista VeloCloud Orchestrator On-Prem systems, particularly those facing the internet or residing in trusted network zones. Patch availability should be confirmed through vendor channels, and where patches are applied, organizations should consider forensic checks for indicators of compromise consistent with active exploitation. Where patching cannot be done immediately, compensating controls such as network segmentation, access restriction, and enhanced monitoring should be evaluated. The KEV Catalog addition also serves as a reminder to validate vulnerability intake processes—ensuring that exploitation evidence is tracked and that remediation timelines align with risk severity. From a threat landscape perspective, the exploitation of these vulnerabilities aligns with known TTPs where attackers target edge devices and management platforms to gain persistence, move laterally, or disrupt operations. Information exposure flaws like CVE-2025-68686 may support credential harvesting or configuration theft, while command injection vulnerabilities such as CVE-2026-16812 are often leveraged for direct system control or as a pivot point to internal networks. The fact that both are being actively exploited suggests ongoing campaigns that security teams should monitor for in threat intelligence feeds and intrusion detection systems. Looking ahead, organizations should watch for further additions to the KEV Catalog, particularly around similar classes of vulnerabilities in network infrastructure, cloud management tools, and remote access solutions. CISA has indicated it will continue to add vulnerabilities meeting the KEV criteria, so sustained engagement with the catalog—through regular review, subscription to alerts, or integration into vulnerability management workflows—is advisable. Additionally, monitoring vendor security advisories for Fortinet and Arista for updates on mitigations, exploit detection guidance, or patches for related issues will help maintain resilience against evolving threats targeting critical infrastructure components.
Event Type: security
Importance: high
Affected Companies
- Arista Networks
- Fortinet
Affected Sectors
- cloud infrastructure
- government
- networking
- technology
Key Numbers
- Number of vulnerabilities added to KEV Catalog: 2
Timeline
- CISA adds CVE-2025-68686 and CVE-2026-16812 to Known Exploited Vulnerabilities Catalog
- Current runtime date; vulnerability additions treated as current/historical
Frequently Asked Questions
What are the two vulnerabilities added to CISA's KEV Catalog on July 27, 2026?
CISA added CVE-2025-68686 affecting Fortinet FortiOS (exposure of sensitive information to unauthorized actors) and CVE-2026-16812 affecting Arista VeloCloud Orchestrator On-Prem (OS command injection) to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation.
What is BOD 26-04 and how does it relate to the KEV Catalog?
Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of vulnerabilities listed in CISA's KEV Catalog on publicly exposed assets, check for compromise before patching, and defer action on lower-risk issues; while binding only for FCEB, CISA encourages all organizations to adopt this risk-based approach.
What should organizations do in response to these KEV Catalog additions?
Organizations should prioritize patching CVE-2025-68686 and CVE-2026-16812 on publicly exposed assets, assess for potential compromise before applying patches where feasible, and adopt risk-based vulnerability management practices aligned with BOD 26-04 guidance, even if not federal agencies.