CISA Flags Actively Exploited Flaws in Fortinet FortiOS and Arista VeloCloud
Two critical vulnerabilities — CVE-2025-68686 in Fortinet FortiOS and CVE-2026-16812 in Arista VeloCloud Orchestrator — have been added to CISA's Known Exploited Vulnerabilities Catalog due to confirmed active exploitation in the wild. These flaws affect widely deployed network infrastructure components, meaning unpatched systems represent a high-value target for threat actors seeking initial access or lateral movement. The KEV Catalog addition triggers mandatory remediation timelines for federal agencies under BOD 26-04, underscoring that speed of patching on internet-facing assets is critical. Failure to act promptly on KEV-listed vulnerabilities leaves organizations exposed to threats that are no longer theoretical — they are actively being weaponized.
Tactical Insight
Immediate actions
- Apply vendor-supplied patches or mitigations for CVE-2025-68686 (FortiOS) and CVE-2026-16812 (Arista VeloCloud) immediately on all affected systems.
- Audit your asset inventory to identify all internet-exposed instances of FortiOS and VeloCloud Orchestrator within your environment.
- Restrict management interfaces for network appliances to trusted internal networks or VPNs to limit external attack surface.
Long-term improvements
- Subscribe to CISA's KEV Catalog feed and integrate it into your vulnerability management program to automate prioritization of actively exploited flaws.
- Establish an emergency patching SLA (e.g., 48–72 hours) specifically for KEV-listed vulnerabilities affecting publicly exposed assets.
- Maintain a continuously updated and accurate inventory of all network appliances, firmware versions, and exposure status.
Detection measures
- Deploy IDS/IPS signatures and threat intelligence feeds targeting exploitation attempts for newly cataloged CVEs on network perimeter devices.
- Enable centralized logging for all network appliances and configure SIEM alerts for anomalous authentication, configuration changes, or unexpected outbound connections.
- Conduct regular vulnerability scans of internet-facing assets and validate remediation closure within defined SLA windows.