Back to all lessons
Awareness Lessons
3 months ago

CISA Flags Actively Exploited Flaws in Fortinet FortiOS and Arista VeloCloud

Two critical vulnerabilities — CVE-2025-68686 in Fortinet FortiOS and CVE-2026-16812 in Arista VeloCloud Orchestrator — have been added to CISA's Known Exploited Vulnerabilities Catalog due to confirmed active exploitation in the wild. These flaws affect widely deployed network infrastructure components, meaning unpatched systems represent a high-value target for threat actors seeking initial access or lateral movement. The KEV Catalog addition triggers mandatory remediation timelines for federal agencies under BOD 26-04, underscoring that speed of patching on internet-facing assets is critical. Failure to act promptly on KEV-listed vulnerabilities leaves organizations exposed to threats that are no longer theoretical — they are actively being weaponized.

Tactical Insight

Immediate actions

  • Apply vendor-supplied patches or mitigations for CVE-2025-68686 (FortiOS) and CVE-2026-16812 (Arista VeloCloud) immediately on all affected systems.
  • Audit your asset inventory to identify all internet-exposed instances of FortiOS and VeloCloud Orchestrator within your environment.
  • Restrict management interfaces for network appliances to trusted internal networks or VPNs to limit external attack surface.

Long-term improvements

  • Subscribe to CISA's KEV Catalog feed and integrate it into your vulnerability management program to automate prioritization of actively exploited flaws.
  • Establish an emergency patching SLA (e.g., 48–72 hours) specifically for KEV-listed vulnerabilities affecting publicly exposed assets.
  • Maintain a continuously updated and accurate inventory of all network appliances, firmware versions, and exposure status.

Detection measures

  • Deploy IDS/IPS signatures and threat intelligence feeds targeting exploitation attempts for newly cataloged CVEs on network perimeter devices.
  • Enable centralized logging for all network appliances and configure SIEM alerts for anomalous authentication, configuration changes, or unexpected outbound connections.
  • Conduct regular vulnerability scans of internet-facing assets and validate remediation closure within defined SLA windows.