The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies address two actively exploited vulnerabilities—one in Arista's VeloCloud Orchestrator and another in Fortinet's FortiOS—within 21 days after adding them to its Known Exploited Vulnerabilities (KEV) catalog.
Under Binding Operational Directive (BOD) 22-01, the inclusion of these flaws moves the issues from recommended to mandatory for U.S. federal civilian executive branch agencies. The directive imposes a strict remediation deadline, and non-compliance carries direct consequences. Security Affairs reports that one of the newly cataloged entries is CVE-2025-68686, which affects Arista VeloCloud Orchestrator.
Why These Targets Are Critical
The two flaws affect software central to modern network infrastructure. The Arista VeloCloud Orchestrator is a cloud-based management console for SD-WAN deployments, meaning its compromise could expose an attacker to network policies, topology, and control across multiple sites. Fortinet FortiOS is the operating system powering the company's widely deployed firewalls and security appliances, which often protect network perimeters and handle critical access functions.
Security researchers note that attacks targeting management planes and security gateways can yield outsized access. The CISA listing confirms that adversaries are actively exploiting these vulnerabilities in the wild, not merely theorizing about them.
The Impact of a KEV Listing
For agencies under BOD 22-01, the catalog entry triggers a compliance timeline: affected assets must be identified, vendor patches or mitigations applied, and completion documented within the specified window.
For all other organizations, the KEV catalog serves as a high-priority signal. Security teams use it to triage their patch queues, focusing first on vulnerabilities with confirmed active exploitation. This is not the first time FortiOS flaws have appeared in the catalog, a pattern that underscores the persistent targeting of widely used network security products.
Recommended Actions for Operators
Organizations running Arista VeloCloud or Fortinet FortiOS systems should prioritize the following steps: - Immediately audit environments to determine if affected software versions are in use, paying close attention to internet-facing management interfaces. - Test and deploy patches or vendor-recommended workarounds in a staging environment before full rollout. - Strengthen authentication controls, network segmentation, and logging around management consoles and firewalls to detect and contain potential exploitation. - Integrate CISA's KEV feed and vendor security advisories into routine vulnerability management workflows.
While the binding deadline applies specifically to federal agencies, the operational lesson applies broadly. Actively exploited vulnerabilities in core network management and security infrastructure demand rapid attention. The KEV catalog remains one of the most reliable public indicators of real-world threat activity, and timely action on its entries directly mitigates demonstrated risk.
美國網絡安全和基礎設施安全局(CISA)已勒令聯邦機構須於21日內處理兩項 actively exploited 漏洞,分別涉及Arista的VeloCloud Orchestrator及Fortinet的FortiOS,此前這兩項漏洞已被納入其已知被利用漏洞(KEV)目錄。
根據強制性操作指令(BOD)22-01,這些漏洞的納入將相關問題對美國聯邦民事行政分支機構從「建議」級別提升至「強制」修補級別。該指令設有嚴格的修復期限,不合規將直接帶來後果。據Security Affairs報導,其中一項新列入的條目是CVE-2025-68686,影響Arista VeloCloud Orchestrator。
為何這些目標至關重要
兩項漏洞影響現代網絡基礎設施的核心軟件。Arista VeloCloud Orchestrator 是一個用於 SD-WAN 部署的雲端管理控制台,其被入侵可能導致攻擊者獲取跨多個站點的網絡策略、拓撲結構和控制權。Fortinet FortiOS 是驅動該公司廣泛部署的防火牆及安全設備的作業系統,這些設備通常用於保護網絡邊界並處理關鍵訪問功能。
安全研究人員指出,針對管理層面和安全網關的攻擊可造成極大的危害。CISA的目錄清單證實,對手正在實際環境中積極利用這些漏洞,而非僅止於理論層面。
KEV目錄納入的影響
對於受BOD 22-01約束的機構,該目錄條目觸發了合規時間表:必須在指定期限內識別受影響資產、應用供應商補丁或緩解措施,並記錄完成情況。
對所有其他組織而言,KEV目錄作為一個高優先級信號。安全團隊利用它來梳理其補丁優先級,優先處理那些已被證實 actively exploited 的漏洞。這並非FortiOS漏洞首次出現在該目錄中,此模式突顯了針對廣泛使用的網絡安全產品的持續性攻擊。
對營運者的建議行動
營運Arista VeloCloud或Fortinet FortiOS系統的組織應優先執行以下步驟: - 立即審計環境,確定是否使用了受影響的軟件版本,並密切關注面向互聯網的管理接口。 - 在全面部署前,先在測試環境中測試並部署補丁或供應商推薦的緩解措施。 - 加強對管理控制台和防火牆的認證控制、網絡分段和日誌記錄,以偵測和遏制潛在的利用行為。 - 將CISA的KEV資訊來源和供應商安全公告整合到常規漏洞管理工作流程中。
儘管強制期限專門針對聯邦機構,但其營運教訓具有普遍適用性。核心網絡管理和安全基礎設施中 actively exploited 的漏洞需要迅速關注。KEV目錄仍然是現實世界威脅活動最可靠的公共指標之一,及時採取行動處理其條目可直接減輕已證實的風險。
