securityonline.info 7/27/2026, 10:32:58 PM · external

CISA adds Arista VeloCloud RCE and Fortinet FortiOS bypass to KEV

CISA adds Arista VeloCloud RCE and Fortinet FortiOS bypass to KEV
Developing story vulnerability 4 articles tracked
CISA adds Arista VeloCloud and Fortinet FortiOS vulnerabilities to KEV catalogue
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Not in KEV
Patch Patch Available

ON July 27, 2026, CISA added two critical known exploited vulnerabilities (KEVs) to its catalog affecting Arista Networks VeloCloud and Fortinet FortiOS. The vulnerabilities include a high-severity remote code execution (RCE) flaw in VeloCloud (CVE-2026-16812) with a CVSS score of 10.0, and a persistence bypass in FortiOS (CVE-2025-68686) with a CVSS score of 5.9. Both vulnerabilities are actively exploited and patches are available. Organizations are advised to update their systems to the specified versions immediately to mitigate risks.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline