The United States Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) Catalog with two new entries, based on evidence of active exploitation in real-world environments. These are CVE-2025-68686, an information exposure vulnerability in Fortinet FortiOS, and CVE-2026-16812, an OS command injection in Arista VeloCloud Orchestrator On-Prem. These flaws represent frequent attack vectors for malicious actors and pose significant risks to any organization, especially critical infrastructure and government agencies.
The KEV Catalog is a key tool under Binding Operational Directive (BOD) 26-04, which establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. Although the directive is mandatory only for federal entities, CISA strongly recommends that all businesses adopt a risk-based approach to prioritize vulnerability remediation. BOD 26-04 emphasizes that security teams must urgently patch CVEs listed in the KEV that affect publicly exposed assets and grant total control after exploitation, while deferring action for lower-risk vulnerabilities. It also requires verifying whether systems were compromised before applying the patch.
The first vulnerability, CVE-2025-68686, affects Fortinet FortiOS, the operating system powering the company's firewalls and security appliances. This flaw allows an unauthenticated attacker to obtain sensitive information, such as internal configurations, credentials, or traffic data. For a business, exposure of such data can facilitate subsequent attacks, including lateral movement within the network or theft of intellectual property. The severity lies in the fact that many organizations rely on Fortinet to protect their perimeters, and a breach at this level can compromise the entire infrastructure. Cybersecurity teams must immediately assess whether their FortiOS instances are exposed and apply patches provided by the vendor.
Meanwhile, CVE-2026-16812 is an OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem, a platform used to manage SD-WAN networks. An attacker with access to the management interface could execute arbitrary commands on the underlying operating system, equivalent to full remote control of the orchestrator. Since VeloCloud Orchestrator centralizes management of multiple branches and sites, a compromise could allow the adversary to redirect traffic, deploy malicious payloads, or disrupt critical services. Organizations using this solution must prioritize updating without delay, especially those with instances accessible from the internet.
These KEV additions underscore the importance of a proactive vulnerability management strategy. It is not enough to wait for a CVE to become public; companies need continuous scanning, risk assessment, and automated patching processes. They must also maintain an accurate inventory of their technology assets, including network appliances, legacy software, and cloud applications. Lack of visibility is often the Achilles' heel of enterprise cybersecurity.
In this context, having a technology partner like Q2BSTUDIO can make a difference. This software development and technology company offers comprehensive services that address exactly these challenges. For example, in the area of cybersecurity, Q2BSTUDIO performs security audits, penetration testing, and vulnerability analysis, helping organizations identify and fix flaws before they are exploited. Additionally, their expertise in cloud AWS/Azure allows designing secure architectures, automating patches, and managing identities and access in hybrid environments.
Artificial intelligence (AI) plays a growing role in early threat detection. AI agents can analyze traffic patterns, correlate logs, and issue real-time alerts for anomalous behavior. Q2BSTUDIO integrates AI solutions into its security platforms, as well as developing custom software with machine learning components. Likewise, Business Intelligence (BI) tools based on Power BI enable visualization of vulnerability status and patch progress, facilitating strategic decision-making. The combination of custom applications with AI and BI capabilities gives companies a competitive edge in risk management.
For organizations looking to modernize their infrastructure, Q2BSTUDIO's cloud AWS/Azure services include secure migrations, container deployments, and Kubernetes orchestration, all with a security-by-design approach. Process automation, through scripts and CI/CD pipelines, reduces the exposure window to vulnerabilities by speeding up patch application. Moreover, custom software development allows creating specific solutions for asset monitoring, incident management, or integrating threat intelligence feeds.
BOD 26-04 also establishes the obligation to verify whether a system was compromised before the patch. This requires incident response and digital forensics capabilities. Companies can rely on specialized external teams, such as those from Q2BSTUDIO, offering containment, eradication, and recovery services. Combining proprietary solutions with managed services allows organizations to focus on their business while maintaining a strong security posture.
In conclusion, the addition of CVE-2025-68686 and CVE-2026-16812 to CISA's KEV catalog is a reminder that cybersecurity is an ongoing process. Critical vulnerabilities emerge constantly, and reaction speed is decisive. Adopting a risk-based approach, prioritizing remediation of the most dangerous CVEs, and relying on technology allies like Q2BSTUDIO are essential steps to protect digital assets. Investment in AI, BI, cloud, and custom software development tools not only improves security but also drives operational efficiency and business innovation.





