Cookie Consent by Free Privacy Policy Generator

CISA Adds Fortinet and Arista Vulnerabilities to Known Exploited Catalogue

CISA has added two vulnerabilities to its Known Exploited Vulnerabilities catalogue based on evidence of active exploitation in the wild. The first, CVE-2025-68686, is a Fortinet FortiOS vulnerability involving exposure of sensitive information to unauthorised actors. The second, CVE-2026-16812, is the Arista VeloCloud Orchestrator command injection flaw. Both vulnerabilities are being actively exploited, and CISA's Binding Operational Directive requires US federal agencies to patch known exploited vulnerabilities within prescribed timescales. While the directive applies to federal agencies, CISA's KEV catalogue is widely used by organisations globally as a prioritisation tool for vulnerability management, reflecting vulnerabilities that are confirmed to be under active attack rather than theoretical risks.

Why this matters for UK organisations

For UK organisations, CISA's KEV catalogue provides a practical and evidence-based prioritisation framework for patch management. When a vulnerability appears on the KEV list, it means attackers are already using it in real-world operations, which makes it a higher priority than vulnerabilities that are merely disclosed or theoretically exploitable. The inclusion of both Fortinet and Arista vulnerabilities in the same update highlights that network infrastructure and security appliances remain high-value targets for attackers. These are the platforms that control access, enforce security policies and manage connectivity across the organisation, which makes them attractive targets for initial access, lateral movement and persistence. The operational challenge for many UK organisations is that network infrastructure and security appliances are often deployed in distributed environments, managed by third parties, or running firmware versions that are difficult to update without service disruption. This makes it harder to patch quickly, even when vulnerabilities are known to be actively exploited.

What to review

UK businesses should review whether vulnerability management processes actively monitor CISA's KEV catalogue and prioritise patching for known exploited vulnerabilities ahead of other updates. Consider whether you have visibility into which network infrastructure, security appliances and edge devices are deployed across the organisation, including those managed by third parties or hosted in branch offices. Assess whether patching timescales reflect the operational risk of active exploitation, and whether emergency patching processes can be triggered when vulnerabilities are added to the KEV catalogue. Review whether you have an accurate inventory of Fortinet, Arista and other network infrastructure vendors, and whether you can quickly identify which systems are affected when new vulnerabilities are disclosed. Consider whether managed service providers or third-party suppliers are monitoring and patching infrastructure on your behalf, and whether service level agreements include timescales for patching known exploited vulnerabilities. Finally, assess whether compensating controls such as network segmentation, access restrictions or monitoring can reduce risk while patching is in progress, and whether incident response plans account for scenarios where network infrastructure or security appliances may be compromised.

Source: CISA Advisories

News and blog posts
Infosecurity Magazine reports that ransomware groups are increasingly using EDR...
CISA has added two vulnerabilities to its Known Exploited Vulnerabilities...
Today's stories highlight the operational security challenges that come with...
The BBC reports that hundreds of conversations with Anthropic's Claude AI...