U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog

2026-07-28T08:51:37Z551c45e58261b9ad97a66e357d55f35214ef26cdf4a6d21c0a837275cf8a981b
CVE-2025-68686AI securityArista VeloCloud OrchestratorCISA KEVFortinet FortiOSGitLabHugging FaceLockBit5MedusaHVNCMicrosoft 365 phishingQilinRATbrowser hijackingcredential theftdata breachhealthcarehotel Wi-Fi compromisemalwareransomwareremote code executionsupply chain security

What happened

Security Affairs RSS highlights actively exploited vulnerabilities in Arista VeloCloud Orchestrator and Fortinet FortiOS added to CISA’s KEV catalog, a critical GitLab remote-code-execution exploit chain, malware using hidden Windows desktops to hijack browsers and steal data, hotel Wi‑Fi gateway compromises for Microsoft 365 credential theft, major ransomware activity, and large-scale personal and health-data breaches. It also reports an AI-agent compromise involving Hugging Face and broader malware campaigns.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
551c45e58261b9ad97a66e357d55f35214ef26cdf4a6d21c0a837275cf8a981b
Enrichment time
2026-07-28T08:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.