CISA Adds Two Actively Exploited Vulnerabilities to KEV Catalog
CISA has updated its Known Exploited Vulnerabilities (KEV) catalog to include two new flaws affecting Fortinet and Arista products that are currently being targeted by malicious actors. Organizations are urged to prioritize patching these systems to prevent potential compromise.

English Brief
CISA has updated its Known Exploited Vulnerabilities (KEV) catalog to include two new flaws affecting Fortinet and Arista products that are currently being targeted by malicious actors. Organizations are urged to prioritize patching these systems to prevent potential compromise.
الموجز العربي
وكالة الأمن السيبراني الأمريكية (CISA) تضيف ثغرتين مستغلتين فعلياً إلى قائمة الثغرات المعروفة
قامت وكالة الأمن السيبراني الأمريكية (CISA) بتحديث قائمة الثغرات الأمنية المستغلة (KEV) لتشمل ثغرتين جديدتين تؤثران على منتجات Fortinet و Arista، حيث يتم استغلالهما حالياً من قبل جهات ضارة. يُنصح المؤسسات بالإسراع في تحديث أنظمتها لمنع أي اختراق محتمل.
- 1Identify affected assets: Fortinet FortiOS and Arista VeloCloud Orchestrator (On-Prem).
- 2Check vendor portals for latest firmware/security patches for CVE-2025-68686 and CVE-2026-16812.
- 3Apply patches immediately.
English Advisory
// Intelligence Summary
CISA has expanded its Known Exploited Vulnerabilities (KEV) catalog with two vulnerabilities: CVE-2025-68686 (Fortinet FortiOS) and CVE-2026-16812 (Arista VeloCloud Orchestrator). Both vulnerabilities are confirmed to be actively exploited in the wild, necessitating immediate remediation as per Binding Operational Directive (BOD) 26-04.
التقرير العربي
// ملخص استخباراتي
قامت وكالة CISA بتوسيع قائمة الثغرات الأمنية المعروفة والمستغلة (KEV) لتشمل ثغرتين: CVE-2025-68686 (في منتج Fortinet FortiOS) و CVE-2026-16812 (في منتج Arista VeloCloud Orchestrator). تم تأكيد تعرض هاتين الثغرتين للاستغلال الفعلي، مما يتطلب معالجة فورية وفقاً للتوجيه التشغيلي الإلزامي (BOD) 26-04.
// Technical Context
CVE-2025-68686 is identified as an exposure of sensitive information vulnerability within Fortinet FortiOS. CVE-2026-16812 is identified as an OS command injection vulnerability within the Arista VeloCloud Orchestrator on-premise solution. Both flaws permit unauthorized actors to interact with systems in ways that deviate from standard security expectations.
// السياق الفني
تُصنف الثغرة CVE-2025-68686 على أنها ثغرة كشف معلومات حساسة في نظام Fortinet FortiOS. بينما تُصنف الثغرة CVE-2026-16812 على أنها ثغرة حقن أوامر نظام التشغيل في حل Arista VeloCloud Orchestrator المحلي (On-Prem). تسمح كلتا الثغرتين للجهات غير المصرح لها بالتفاعل مع الأنظمة بطرق تتجاوز الضوابط الأمنية القياسية.
// Exposure Notes
These vulnerabilities represent significant risks, particularly to enterprises utilizing these specific networking and infrastructure management solutions. The nature of command injection and sensitive data exposure makes these assets high-value targets for lateral movement and data exfiltration.
// ملاحظات التعرض
تمثل هذه الثغرات مخاطر كبيرة، لا سيما للمؤسسات التي تستخدم هذه الحلول الخاصة بالشبكات وإدارة البنية التحتية. طبيعة حقن الأوامر وكشف البيانات الحساسة تجعل من هذه الأصول أهدافاً ذات قيمة عالية لمحاولات الاختراق الجانبي وتسريب البيانات.
// Defensive Priority
Organizations must prioritize patching these vulnerabilities immediately. Systems should be audited for signs of prior compromise consistent with the exploitation of these specific CVEs, as per guidance in BOD 26-04.
// أولوية الدفاع
يجب على المؤسسات إعطاء الأولوية القصوى لتطبيق التحديثات الأمنية فوراً. يجب فحص الأنظمة بحثاً عن أي علامات لاختراق مسبق بما يتوافق مع إرشادات BOD 26-04.
Mitigation Checklist
- 1Identify affected assets: Fortinet FortiOS and Arista VeloCloud Orchestrator (On-Prem).
- 2Check vendor portals for latest firmware/security patches for CVE-2025-68686 and CVE-2026-16812.
- 3Apply patches immediately.
- 4Review system logs for unauthorized access or execution commands targeting these CVEs.
- 5Restrict management interface access to trusted networks only.
قائمة إجراءات التخفيف
- 1تحديد الأصول المتأثرة: منتجات Fortinet FortiOS و Arista VeloCloud Orchestrator.
- 2التحقق من مواقع الموردين للحصول على أحدث التحديثات الأمنية للثغرتين المذكورتين.
- 3تطبيق التحديثات بشكل فوري.
- 4مراجعة سجلات النظام بحثاً عن أي وصول غير مصرح به أو أوامر تنفيذ مشبوهة.
- 5تقييد الوصول إلى واجهات الإدارة وحصرها في الشبكات الموثوقة فقط.
- Source: CISA Alerts
# 1. Identify affected assets: Fortinet FortiOS and Arista VeloCloud Orchestrator (On-Prem).
# 2. Check vendor portals for latest firmware/security patches for CVE-2025-68686 and CVE-2026-16812.
# 3. Apply patches immediately.
# 4. Review system logs for unauthorized access or execution commands targeting these CVEs.
# 5. Restrict management interface access to trusted networks only.