CISA KEV Additions: Arista VeloCloud and FortiOS Flaws Now Exploited
ID: f25ce78b-ffae-5a68-a961-7c5b7de54765
STIX ID: report--f25ce78b-ffae-5a68-a961-7c5b7de54765
Feed Name: securityonline.info
Threat Score
CISA added two known-exploited vulnerabilities to its KEV catalog: a critical, unauthenticated remote OS command injection in Arista VeloCloud Orchestrator (CVE-2026-16812, CVSS 10.0) and a FortiOS persistence/symlink bypass (CVE-2025-68686). Both are confirmed exploited in the wild; vendors have published advisories and fixes—organizations should apply the listed patches immediately and hunt for signs of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
