THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2025-68686 affecting Fortinet FortiOS, which has a CVSS score of 5.3, and CVE-2026-16812 impacting Arista VeloCloud Orchestrator, rated at 10.0. The Fortinet issue allows unauthorized access to sensitive information post-compromise, while the Arista bug could let attackers invoke privileged functions, jeopardizing network data integrity.
Federal agencies must fix these vulnerabilities by specific deadlines: July 20, 2026, for Arista and August 10, 2026, for Fortinet. Organizations are advised to apply security updates promptly and review the KEV catalog.