logo

CISA KEV Additions: Arista VeloCloud and FortiOS Flaws Now Exploited

ID: f25ce78b-ffae-5a68-a961-7c5b7de54765

STIX ID: report--f25ce78b-ffae-5a68-a961-7c5b7de54765

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

Author: Do Son

...
...

CISA added two known-exploited vulnerabilities to its KEV catalog: a critical, unauthenticated remote OS command injection in Arista VeloCloud Orchestrator (CVE-2026-16812, CVSS 10.0) and a FortiOS persistence/symlink bypass (CVE-2025-68686). Both are confirmed exploited in the wild; vendors have published advisories and fixes—organizations should apply the listed patches immediately and hunt for signs of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.