CISA KEV Catalog Addition: Fortinet FortiOS and Arista VeloCloud Orchestrator Vulnerabilities
First seen Jul 28, 2026 · Updated Jul 28, 2026
CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: a sensitive information exposure flaw in Fortinet FortiOS (CVE-2025-68686) and an OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem (CVE-2026-16812). Both are confirmed to be exploited in the wild and require urgent remediation under BOD 26-04 for federal agencies, with CISA recommending all organizations prioritize patching.
Technical Analysis
CVE-2025-68686 affects Fortinet FortiOS and involves exposure of sensitive information to an unauthorized actor, which could allow attackers to harvest credentials, session tokens, or configuration data from vulnerable devices. CVE-2026-16812 is an OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem, enabling attackers to execute arbitrary system commands, potentially leading to full device compromise on SD-WAN orchestration infrastructure. Both vulnerabilities affect network perimeter and edge infrastructure commonly exposed to the internet, making them attractive targets for initial access and lateral movement. Organizations running AI agent orchestration, RAG pipelines, or LLM tool-use frameworks behind Fortinet firewalls or Arista SD-WAN infrastructure face elevated risk: compromise of these network devices could expose API keys, credentials, or internal traffic used by agent systems, and command injection on the orchestrator could provide attackers a pivot point into internal networks hosting agent infrastructure.
Affected Systems
Fortinet FortiOS (specific vulnerable versions per Fortinet advisory for CVE-2025-68686); Arista VeloCloud Orchestrator On-Prem deployments (specific vulnerable versions per Arista advisory for CVE-2026-16812)
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) provided in source data; refer to CISA KEV Catalog and vendor advisories for detection guidance
Remediation Steps
- 1
Apply vendor patches
Immediately apply Fortinet's security update addressing CVE-2025-68686 and Arista's patch for CVE-2026-16812 on all affected FortiOS and VeloCloud Orchestrator On-Prem deployments.
- 2
Check for prior compromise
Per BOD 26-04 guidance, review logs and system state to determine whether these vulnerabilities were exploited prior to patching, especially on publicly exposed assets.
- 3
Restrict public exposure
Limit management interfaces and administrative access to FortiOS and VeloCloud Orchestrator instances from the public internet; enforce VPN or allow-listing for administrative access.
- 4
Rotate credentials and keys
If devices were exposed prior to patching, rotate any credentials, API keys, or tokens that could have been exposed, particularly those used by downstream automation or AI agent systems relying on these network devices.
- 5
Monitor KEV Catalog
Integrate CISA's KEV Catalog into vulnerability management workflows and prioritize remediation of listed CVEs on internet-facing assets.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.