【Vulnerability Alert】CISA Added 3 Known Exploited Vulnerabilities to the KEV Catalog (2026/07/27-2026/08/02)

publish date : 2026-08-07 update date : 2026-08-07

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026080401080808 Publication Time 2026-08-04 13:56:09
Incident Type ANA-Vulnerability Alert Discovery Time 2026-08-04 13:56:09
Impact Level Low  
[Subject]
【Vulnerability Alert】CISA Added 3 Known Exploited Vulnerabilities to the KEV Catalog (2026/07/27-2026/08/02)
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202608-00000001

【CVE-2025-68686】Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVSS v3.1: 5.9)
【Whether exploited by ransomware: Unknown】Fortinet FortiOS contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability, which may allow an unauthorized remote attacker to bypass patches developed for a symbolic link persistence mechanism observed in certain post-exploitation cases through specially crafted HTTP requests. An attacker must first successfully compromise the product through other vulnerabilities at the file system level before this vulnerability can be exploited.

【CVE-2026-16812】Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability (CVSS v3.1: 10.0)
【Whether exploited by ransomware: Unknown】Arista VeloCloud Orchestrator On-Prem contains an operating system command injection vulnerability, which may allow a remote attacker to access internal privileged functions and impact the VCO host. Successful exploitation of this vulnerability may compromise the confidentiality, integrity, and availability of the Orchestrator and the data it manages.

【CVE-2026-20316】Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability (CVSS v3.1: 5.3)
【Whether exploited by ransomware: Unknown】Cisco Secure Firewall Management Center contains a Use of Hard-coded Password vulnerability, which may allow an unauthenticated remote attacker to log in to an affected device using a low-privilege account and access sensitive data within the affected system.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

【CVE-2025-68686】Please refer to the affected versions listed by the official vendor https://fortiguard.fortinet.com/psirt/FG-IR-25-934

【CVE-2026-16812】Please refer to the affected versions listed by the official vendor https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144

【CVE-2026-20316】Please refer to the affected versions listed by the official vendor https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh

[Recommended Actions]

【CVE-2025-68686】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://fortiguard.fortinet.com/psirt/FG-IR-25-934

【CVE-2026-16812】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144

【CVE-2026-20316】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh

[Reference]

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center