CISA Flags Fortinet FortiOS Info Exposure (CVE‑2025‑68686) and Arista VeloCloud OS Command Injection (CVE‑2026‑16812) as Known Exploited Vulnerabilities
What It Is — The Cybersecurity & Infrastructure Security Agency (CISA) added two CVEs to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active, real‑world exploitation. One flaw (CVE‑2025‑68686) in Fortinet FortiOS can leak sensitive configuration data to unauthenticated actors; the other (CVE‑2026‑16812) in Arista VeloCloud Orchestrator permits unauthenticated OS‑level command execution.
Exploitability — Both vulnerabilities are being exploited in the wild; public exploit code and attacker‑use reports exist. CVSS scores are 8.8 (FortiOS) and 9.3 (VeloCloud), placing them in the High severity band.
Affected Products
- Fortinet FortiOS (all supported releases prior to the vendor‑issued patch).
- Arista VeloCloud Orchestrator (on‑premises deployment, versions prior to the security update).
Why It Matters for Compliance & Audit Readiness
- Control Mapping: These flaws map directly to SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations) – failure to remediate can be interpreted as ineffective change‑control processes.
- Continuous Evidence: Demonstrating timely patching and verification provides audit‑ready evidence that your organization follows a risk‑based vulnerability‑management program, a requirement under BOD 26‑04 and increasingly demanded by enterprise customers.
- Trust Center Proof: Capturing remediation tickets, patch‑deployment logs, and post‑remediation scans feeds into a Trust Center dashboard, giving stakeholders a real‑time view of your security posture.
Recommended Actions
- Inventory all FortiOS and VeloCloud assets; tag any that are internet‑facing.
- Prioritize patching per BOD 26‑04 – treat KEV entries as “high‑risk” and apply vendor patches within the agency‑mandated 48‑hour window (or faster for critical services).
- Document the remediation workflow (ticket creation, patch application, verification scan) and store logs in a tamper‑evident repository for SOC 2 evidence.
- Validate that the patch eliminates the exploit by running the vendor‑provided test scripts or an independent vulnerability scan.
- Update your continuous‑compliance platform (e.g., Verisq Trust Center) to reflect the closed control gap and generate audit‑ready reports.
Source: CISA Advisory – Two Known Exploited Vulnerabilities Added to KEV Catalog (July 27 2026)