[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fOqV4rP1SX3FiNYehOz-Y5_Np2cOXQnFrEHZEMLE8x9o":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"bb715c1f-aef1-4bf4-9326-f3bec6cff4e7","cisa-flags-actively-exploited-flaws-in-fortinet-fortios-and-arista-velocloud","ede5c736-beae-4961-9452-6189baa71ba6","CISA Flags Actively Exploited Flaws in Fortinet FortiOS and Arista VeloCloud","Two critical vulnerabilities — CVE-2025-68686 in Fortinet FortiOS and CVE-2026-16812 in Arista VeloCloud Orchestrator — have been added to CISA's Known Exploited Vulnerabilities Catalog due to confirmed active exploitation in the wild. These flaws affect widely deployed network infrastructure components, meaning unpatched systems represent a high-value target for threat actors seeking initial access or lateral movement. The KEV Catalog addition triggers mandatory remediation timelines for federal agencies under BOD 26-04, underscoring that speed of patching on internet-facing assets is critical. Failure to act promptly on KEV-listed vulnerabilities leaves organizations exposed to threats that are no longer theoretical — they are actively being weaponized.","**Immediate actions:**\n- Apply vendor-supplied patches or mitigations for CVE-2025-68686 (FortiOS) and CVE-2026-16812 (Arista VeloCloud) immediately on all affected systems.\n- Audit your asset inventory to identify all internet-exposed instances of FortiOS and VeloCloud Orchestrator within your environment.\n- Restrict management interfaces for network appliances to trusted internal networks or VPNs to limit external attack surface.\n\n**Long-term improvements:**\n- Subscribe to CISA's KEV Catalog feed and integrate it into your vulnerability management program to automate prioritization of actively exploited flaws.\n- Establish an emergency patching SLA (e.g., 48–72 hours) specifically for KEV-listed vulnerabilities affecting publicly exposed assets.\n- Maintain a continuously updated and accurate inventory of all network appliances, firmware versions, and exposure status.\n\n**Detection measures:**\n- Deploy IDS\u002FIPS signatures and threat intelligence feeds targeting exploitation attempts for newly cataloged CVEs on network perimeter devices.\n- Enable centralized logging for all network appliances and configure SIEM alerts for anomalous authentication, configuration changes, or unexpected outbound connections.\n- Conduct regular vulnerability scans of internet-facing assets and validate remediation closure within defined SLA windows.",[12,13,14,15,16,17,18,19,20],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management Planning","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 RA-5: Vulnerability Monitoring and Scanning","CISA BOD 26-04: Reducing the Significant Risk of Known Exploited Vulnerabilities","CISA KEV Catalog","NIST CSF 2.0 ID.RA-1: Asset Vulnerabilities are Identified and Documented","NIST CSF 2.0 RS.MI-3: Newly Identified Vulnerabilities are Mitigated or Documented as Accepted Risks","published","2026-07-27T22:22:07.322018+00:00","2026-07-27T22:22:07.191+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F07\u002F27\u002Fcisa-adds-two-known-exploited-vulnerabilities-catalog","cisa-adds-two-known-exploited-vulnerabilities-to-catalog-b02310","CISA Adds Two Known Exploited Vulnerabilities to Catalog",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]