HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Advisory

CISA Flags Fortinet FortiOS Info Exposure (CVE‑2025‑68686) and Arista VeloCloud OS Command Injection (CVE‑2026‑16812) as Known Exploited Vulnerabilities

CISA added CVE‑2025‑68686 (FortiOS data leak) and CVE‑2026‑16812 (VeloCloud command injection) to its KEV catalog after verifying active exploitation. Organizations must treat these as high‑risk and remediate promptly to maintain SOC 2 compliance and audit readiness.

LiveThreat™ Intelligence · 📅 July 28, 2026· 📰 cisa.gov
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
cisa.gov

CISA Flags Fortinet FortiOS Info Exposure (CVE‑2025‑68686) and Arista VeloCloud OS Command Injection (CVE‑2026‑16812) as Known Exploited Vulnerabilities

What It Is — The Cybersecurity & Infrastructure Security Agency (CISA) added two CVEs to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active, real‑world exploitation. One flaw (CVE‑2025‑68686) in Fortinet FortiOS can leak sensitive configuration data to unauthenticated actors; the other (CVE‑2026‑16812) in Arista VeloCloud Orchestrator permits unauthenticated OS‑level command execution.

Exploitability — Both vulnerabilities are being exploited in the wild; public exploit code and attacker‑use reports exist. CVSS scores are 8.8 (FortiOS) and 9.3 (VeloCloud), placing them in the High severity band.

Affected Products

  • Fortinet FortiOS (all supported releases prior to the vendor‑issued patch).
  • Arista VeloCloud Orchestrator (on‑premises deployment, versions prior to the security update).

Why It Matters for Compliance & Audit Readiness

  • Control Mapping: These flaws map directly to SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations) – failure to remediate can be interpreted as ineffective change‑control processes.
  • Continuous Evidence: Demonstrating timely patching and verification provides audit‑ready evidence that your organization follows a risk‑based vulnerability‑management program, a requirement under BOD 26‑04 and increasingly demanded by enterprise customers.
  • Trust Center Proof: Capturing remediation tickets, patch‑deployment logs, and post‑remediation scans feeds into a Trust Center dashboard, giving stakeholders a real‑time view of your security posture.

Recommended Actions

  • Inventory all FortiOS and VeloCloud assets; tag any that are internet‑facing.
  • Prioritize patching per BOD 26‑04 – treat KEV entries as “high‑risk” and apply vendor patches within the agency‑mandated 48‑hour window (or faster for critical services).
  • Document the remediation workflow (ticket creation, patch application, verification scan) and store logs in a tamper‑evident repository for SOC 2 evidence.
  • Validate that the patch eliminates the exploit by running the vendor‑provided test scripts or an independent vulnerability scan.
  • Update your continuous‑compliance platform (e.g., Verisq Trust Center) to reflect the closed control gap and generate audit‑ready reports.

Source: CISA Advisory – Two Known Exploited Vulnerabilities Added to KEV Catalog (July 27 2026)

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →