Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-28 ยท updated: 2026-07-28 ยท tags: [incident, kev, au-focus] ยท confidence: high ยท affected_sectors: [technology, government] ยท au_impact: true

CISA Adds Active-Exploited Arista VeloCloud and Fortinet FortiOS Flaws to KEV Catalog

Summary

CISA added Arista VeloCloud and Fortinet FortiOS security flaws to its Known Exploited Vulnerabilities Catalog following active exploitation in the wild.

Details

The US Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) Catalog, adding two major on-premises network edge flaws.

Added Vulnerabilities

  1. Cve 2026 16812 Arista Velocloud Cmd Injection (CVSS 10.0, Critical): An unauthenticated operating system command injection in Arista Networks' VeloCloud Orchestrator (VCO) on-premises web interface.
  2. Cve 2025 68686 Fortios Symlink Bypass (CVSS 5.3, Medium): An unauthenticated HTTP-request bypass targeting Fortinet FortiOS symbolic link persistency patches within compromised environments.

Remediation Mandate

Under Binding Operational Directive (BOD) 26-04, federal civilian agencies must remediate these vulnerabilities immediately.

Australian Significance

The active exploitation of these edge devices highlights a severe threat to Australian organisations. Those governed by APRA CPS 234 or operating critical infrastructure assets under the SOCI Act are advised to execute immediate verification and apply patches to protect their software supply chains.

Related Pages