CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CISA Adds Two Known Exploited Vulnerabilities to Catalog

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3298

As cited

Copy frozen at (site build).

vulnerabilities

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added two vulnerabilities to its Known Exploited Vulnerabilities Catalog: CVE-2025-68686 in Fortinet FortiOS and CVE-2026-16812 in Arista VeloCloud Orchestrator, both showing active exploitation in the wild. The additions underscore CISA's continued effort to maintain a prioritized list of vulnerabilities being actively exploited, with federal agencies required under Binding Operational Directive 26-04 to prioritize patching these high-risk flaws on publicly exposed systems.

Why it matters: Federal civilian agencies must prioritize patching these two vulnerabilities on externally facing assets; all organizations should treat KEV Catalog entries as remediation priorities to reduce risk of compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added two vulnerabilities to its Known Exploited Vulnerabilities Catalog: CVE-2025-68686 in Fortinet FortiOS and CVE-2026-16812 in Arista VeloCloud Orchestrator, both showing active exploitation in the wild. The additions underscore CISA's continued effort to maintain a prioritized list of vulnerabilities being actively exploited, with federal agencies required under Binding Operational Directive 26-04 to prioritize patching these high-risk flaws on publicly exposed systems.

Why it matters: Federal civilian agencies must prioritize patching these two vulnerabilities on externally facing assets; all organizations should treat KEV Catalog entries as remediation priorities to reduce risk of compromise.

VendorsFortinet
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary