ON July 27, 2026, CISA added two critical known exploited vulnerabilities (KEVs) to its catalog affecting Arista Networks VeloCloud and Fortinet FortiOS. The vulnerabilities include a high-severity remote code execution (RCE) flaw in VeloCloud (CVE-2026-16812) with a CVSS score of 10.0, and a persistence bypass in FortiOS (CVE-2025-68686) with a CVSS score of 5.9. Both vulnerabilities are actively exploited and patches are available. Organizations are advised to update their systems to the specified versions immediately to mitigate risks.
CISA adds Arista VeloCloud RCE and Fortinet FortiOS bypass to KEV
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
OS command injection flaw hits Arista VeloCloud, CISA issues alert
cybersixt.com
-
CISA adds FortiOS info leak CVE-2025-68686 to KEV, urges patch
cybersixt.com
-
CISA adds Arista VeloCloud RCE and Fortinet FortiOS bypass to KEV
securityonline.info
-
Arista Warns of Actively Exploited VeloCloud Orchestrator Bug
cybersixt.com