CISA Adds Critical Arista and Fortinet Flaws to Known Exploited Vulnerabilities Catalog
CISA added two actively exploited vulnerabilities to its KEV catalog on July 27, 2026: a critical CVSS 10.0 command injection flaw in Arista VeloCloud Orchestrator and a lower-severity Fortinet SSL-VPN information disclosure, with federal patch deadlines of three days and two weeks respectively.
On July 27, 2026, CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog — a critical command injection flaw in Arista’s VeloCloud Orchestrator and a lower-severity information disclosure bug in Fortinet’s FortiOS SSL-VPN — with mandatory patch deadlines for federal agencies that reflect the different risks each poses.
The Arista vulnerability, CVE-2026-16812, is a maximum-severity (CVSS 10.0) unauthenticated OS command injection in on-premises VeloCloud Orchestrator deployments, and BleepingComputer reports it is being actively exploited as a zero-day. Federal agencies must patch by July 30, a three-day window that underscores the urgency of a flaw that allows remote code execution without any authentication on a device that sits at the edge of enterprise networks.
The second addition, CVE-2025-68686, is an information disclosure vulnerability in Fortinet’s FortiOS SSL-VPN with a CVSS score of 5.3 and a patch deadline of August 10. While substantially less severe, it still carries the active-exploitation tag that lands it in the KEV catalog, and SSL-VPN appliances have been a consistent target for initial access in recent years.
The contrasting deadlines are a useful reminder of how the KEV program works: it doesn’t just list vulnerabilities that are being attacked — it sets a pace. A CVSS 10.0 command injection on a network orchestrator gets three days. An information disclosure, even one being actively exploited, gets two weeks. That granularity is what makes the catalog a practical operational tool rather than a generic alert feed.
Both flaws sit in appliances that are built to be reachable from the outside, which is why they keep showing up in the KEV catalog. The Arista zero-day in particular is a reminder that when a patch drops for a CVSS 10.0 bug in an edge device, the time between the advisory and the first exploitation attempts is often measured in hours, not days. CISA’s three-day deadline formalizes that reality into a mandate.
For defenders, the takeaway is the same one the KEV catalog has been reinforcing since it launched: edge-device vulnerabilities on the list are not theoretical. If a CVE appears here, the evidence of active exploitation is already in hand, and the clock starts the moment the entry is published.