CISA's list that day
27 July 2026
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Fortinet FortiOS and Arista VeloCloud Orchestrator. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-16812On-Prem OS Command Injection | Arista VeloCloud Orchestrator | Patch nowForensic triage required by CISA | 0.01 | ||
| CVE-2025-68686Exposure of Sensitive Information to an Unauthorized Actor | Fortinet FortiOS | Patch soon | 0.30 |