U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog
Overview
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities associated with Arista VeloCloud Orchestrator and Fortinet's FortiOS to its Known Exploited Vulnerabilities catalog. The specific vulnerability for Arista is identified as CVE-2025-68686. This inclusion indicates that these flaws are being actively exploited, posing a significant risk to users of these products. Organizations using Arista's VeloCloud Orchestrator or Fortinet's FortiOS should take immediate action to address these vulnerabilities to safeguard their systems from potential attacks. The urgency of this update emphasizes the need for timely patching and monitoring of network security.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Arista VeloCloud Orchestrator, Fortinet FortiOS
- Action Required: Organizations should apply any available patches for FortiOS and VeloCloud Orchestrator as soon as possible.
- Timeline: Newly disclosed
Original Article Summary
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the KeV catalog: CVE-2025-68686 is an […]
Impact
Arista VeloCloud Orchestrator, Fortinet FortiOS
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Organizations should apply any available patches for FortiOS and VeloCloud Orchestrator as soon as possible. Additionally, users should review their configurations and security settings to mitigate potential risks associated with these vulnerabilities.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Fortinet, Vulnerability, and 2 more.