CISA Adds Two Known Exploited Vulnerabilities to Catalog

Summary

CISA has added two new vulnerabilities, CVE-2025-68686 and CVE-2026-16812, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These vulnerabilities affect Fortinet FortiOS and Arista VeloCloud Orchestrator, respectively, and pose significant risks. The article also references Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize remediation of these high-risk vulnerabilities.

IFF Assessment

FOE

The addition of known exploited vulnerabilities to CISA's catalog indicates active threats that defenders must address, posing a risk to systems and data.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: July 30, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should be aware of these newly cataloged vulnerabilities and prioritize patching them, especially on publicly exposed assets. The inclusion in CISA's KEV catalog signifies active exploitation, meaning these vulnerabilities are likely being leveraged by threat actors. This highlights the ongoing need for robust vulnerability management and timely patching to mitigate risks.

Read Full Story →