THE Known Exploited Vulnerabilities (KEV) Catalog, maintained by CISA, serves as a crucial resource for the cybersecurity community to manage and prioritize vulnerabilities that have been actively exploited in the wild. The catalog includes vulnerabilities such as CVE-2026-16812, an OS command injection vulnerability in Arista VeloCloud Orchestrator, which could allow remote attackers to compromise data integrity and availability.
Organizations are encouraged to apply mitigations per vendor guidelines and adhere to CISA’s BOD 26-04 for security updates. Users can also nominate new vulnerabilities for catalog inclusion and access the catalog in various formats including CSV and JSON.