As cited
Copy frozen at (site build).
vulnerabilities
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA added two vulnerabilities to its Known Exploited Vulnerabilities Catalog: CVE-2025-68686 in Fortinet FortiOS and CVE-2026-16812 in Arista VeloCloud Orchestrator, both showing active exploitation in the wild. The additions underscore CISA's continued effort to maintain a prioritized list of vulnerabilities being actively exploited, with federal agencies required under Binding Operational Directive 26-04 to prioritize patching these high-risk flaws on publicly exposed systems.
Why it matters: Federal civilian agencies must prioritize patching these two vulnerabilities on externally facing assets; all organizations should treat KEV Catalog entries as remediation priorities to reduce risk of compromise.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA added two vulnerabilities to its Known Exploited Vulnerabilities Catalog: CVE-2025-68686 in Fortinet FortiOS and CVE-2026-16812 in Arista VeloCloud Orchestrator, both showing active exploitation in the wild. The additions underscore CISA's continued effort to maintain a prioritized list of vulnerabilities being actively exploited, with federal agencies required under Binding Operational Directive 26-04 to prioritize patching these high-risk flaws on publicly exposed systems.
Why it matters: Federal civilian agencies must prioritize patching these two vulnerabilities on externally facing assets; all organizations should treat KEV Catalog entries as remediation priorities to reduce risk of compromise.
- Source published
- First seen by Cybersecurity Tracker