U.S. CISA adds Cisco Catalyst SD-WAN, Arista Extensible Operating System (EOS), and Google Chromium V8 flaws to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-11645 | Out-of-Bounds Read/Write in Google Chrome V8 Enables In-Sandbox Code Execution CVE-2026-11645 is an out-of-bounds read and write (CWE-125/CWE-787) in V8, the JavaScript engine used by Google Chrome and Chromium. A remote attacker triggers the flaw by luring a user to a crafted HTML page, where malicious script causes V8 to read and write outside allocated memory buffers. Successful exploitation allows the attacker to execute arbitrary code inside the browser's security sandbox, providing limited privileges within that process rather than full system compromise. All Google Chrome versions prior to 149.0.7827.103 are affected, along with the Chromium V8 component identified by CISA. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-09, and related headlines describe an actively exploited Chrome V8 zero-day, though no public proof-of-concept is known and ransomware use is unconfirmed. Do: Update Google Chrome to 149.0.7827.103 or later and restart the browser to load the patched V8, prioritizing systems exposed to untrusted web content; because the flaw is in CISA's KEV catalog, federal agencies must apply vendor mitigations or follow BOD 22-01 guidance within the required timeframe. Organizations running Chromium-derived browsers (e.g., Edge, Brave, Opera) should apply vendor updates that incorporate the patched V8 as they become available. Restricting browsing of untrusted sites from high-value systems is a reasonable interim measure, and no public exploit code is known at this time. | 8.8 | 2% | KEV |
| massbillions of users (Chrome holds roughly two-thirds of global browser market share) | |
| CVE-2026-20127 | Authentication Bypass in Cisco Catalyst SD-WAN Controller, Manager, Validator A flaw in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller (formerly vSmart), Manager (formerly vManage), and Validator (formerly vBond) allows an unauthenticated, remote attacker to bypass authentication by sending crafted requests to an affected system. A successful exploit grants the attacker access as an internal, high-privileged, non-root user on the SD-WAN Controller, from which they can reach NETCONF and manipulate the network configuration of the entire SD-WAN fabric. Any organization operating these Cisco SD-WAN control-plane components is affected, and the critical CVSS 10.0 score reflects full network scope with no privileges or user interaction required. The flaw is confirmed exploited in the wild: CISA added it to the KEV on 2026-02-25, Cisco has confirmed active exploitation (including a compromise of a communications service provider), and Five Eyes allies have issued an active-exploitation warning, with EPSS at 88.2% (100th percentile). Do: Upgrade affected Catalyst SD-WAN Controller, Manager, and Validator components per Cisco's PSIRT advisory (fixed versions are not specified in this data), and prioritize patching given confirmed in-the-wild exploitation. Follow CISA Emergency Directive 26-03 and the CISA Hunt & Hardening Guidance for Cisco SD-WAN Devices: hunt for compromise indicators such as unexpected high-privileged non-root logins and unauthorized NETCONF configuration changes, and restrict internet exposure of SD-WAN management interfaces. Where mitigations are unavailable, adhere to applicable BOD 22-01 cloud guidance or discontinue use of the product. | 10.0 | 88% | KEV |
| large≈10,000–100,000 controller/manager/validator deployments across enterprise and service-provider SD-WAN fabrics (Cisco SD-WAN is a market-leading enterprise… | |
| CVE-2026-20182 | Authentication Bypass in Cisco Catalyst SD-WAN Control Components CVE-2026-20182 is a critical authentication flaw (CWE-287) in the control-connection peering authentication of Cisco Catalyst SD-WAN Controller (formerly vSmart), Manager (formerly vManage), and Validator (formerly vBond). Because the peering authentication mechanism does not work properly, an unauthenticated, remote attacker can send crafted requests during the control-connection handshake and log in to the controller as an internal, high-privileged, non-root user without valid credentials. With this access, the attacker can reach NETCONF and manipulate network configuration across the entire SD-WAN fabric. Any organization running these Catalyst SD-WAN control components is affected, and the flaw carries a CVSS 3.1 score of 10.0 and a 91.5% EPSS score. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-05-14, confirming exploitation in the wild, amid a series of exploited Cisco SD-WAN zero-days including a compromise at a communications service provider. Do: Upgrade affected Catalyst SD-WAN Controller, Manager, and Validator components to the fixed releases identified in Cisco's May 2026 advisory (version numbers are not provided in this data). Use the advisory's 'show control connections' guidance to inspect control-connection handshaking for anomalies and audit for unauthorized high-privileged non-root accounts and unexpected NETCONF sessions. Operators — especially federal agencies — should follow CISA Emergency Directive 26-03 and CISA's Hunt & Hardening Guidance for Cisco SD-WAN Devices, including restricting internet exposure of SD-WAN management interfaces until patched. | 10.0 | 92% | KEV |
| largeon the order of tens of thousands of affected control-plane systems (controllers, managers, validators) across enterprise, service-provider, and government… | |
| CVE-2026-20245 | Command Injection as Root in Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) contains an improper encoding or escaping of output flaw (CWE-116) in its handling of user-supplied files. An attacker who already has authenticated access to the system can trigger it by supplying a crafted file, because the file's contents are not properly escaped before being processed. Successful exploitation yields arbitrary command execution with root privileges, giving the attacker full control of the SD-WAN management platform. Organizations running Cisco Catalyst SD-WAN Manager/vManage to manage their SD-WAN fabric are affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-09, indicating active exploitation, though no public proof-of-concept is known and ransomware use has not been confirmed. Do: Apply the fixed release per Cisco's security advisory (specific fixed versions are not included in the available data), and prioritize this patch given the KEV listing. Because the flaw requires authenticated local access, restrict management-plane access to trusted administrators and networks, review privileged accounts on the manager, and audit the system for unexpected processes or changes. Federal agencies must follow the KEV required action under BOD 22-01 (mitigate per vendor instructions or discontinue use). | 7.8 | 25% | KEV |
| largeon the order of tens of thousands of deployments worldwide | |
| CVE-2026-7473 | Incomplete Tunnel Protocol Verification in Arista EOS Exploited in the Wild Arista EOS switches configured for tunnel decapsulation — VXLAN, decap-groups, or a GRE tunnel interface — fail to verify the tunnel protocol type of incoming packets before decapsulating them (CWE-1023, incomplete comparison with missing factors). An attacker can send an unexpected type of tunneled packet whose destination IP matches the switch's configured decapsulation IP, causing the switch to incorrectly decapsulate and forward it as if it belonged to the configured tunnel. The result is a traffic-integrity problem — packets are processed and delivered through a path they were never intended for — reflected in the CVSS 4.0 score of 6.9 as network-triggered, unauthenticated, integrity-only impact with no confidentiality or availability loss. Only deployments running Arista EOS with a tunnel decapsulation configuration are affected; sites without VXLAN/decap-group/GRE decapsulation are not exposed to this flaw. Exploitation in the wild has been reported — CISA added the issue to the Known Exploited Vulnerabilities catalog on 2026-06-09 — though no public proof-of-concept is known and ransomware use has not been confirmed. Do: Inventory Arista EOS devices for tunnel decapsulation configuration (VXLAN, decap-groups, or GRE tunnel interfaces) and check whether the configured decapsulation IP is reachable from untrusted networks. Upgrade to a fixed EOS release per Arista's advisory for CVE-2026-7473 (fixed versions are not specified in the available data) or apply the vendor's recommended mitigation, such as filtering unexpected tunnel traffic destined to the decapsulation IP; federal agencies must remediate within the BOD 22-01 timeline following the 2026-06-09 KEV addition. Because the scored impact is limited to traffic-handling integrity, prioritize the exposure assessment, but do not defer patching given confirmed in-the-wild exploitation. | 6.9 | 1% | KEV |
| large≈tens of thousands to ~100,000 systems/sites (VXLAN decap-groups and GRE decapsulation are common configurations in Arista data-center fabrics) |
Full article446 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Catalyst SD-WAN, Arista Extensible Operating System (EOS), and Google Chromium V8 flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added BerriAI LiteLLM and Check Point Security Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog.
The two flaws added to the catalog are:
- CVE-2026-7473 (CVSS score v4.0 of 6.9) Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
- CVE-2026-11645 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
- CVE-2026-20245 (CVSS score v4.0 of 7.1) Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
CVE-2026-7473 is a vulnerability in Arista EOS that affects systems configured for tunnel decapsulation (such as VXLAN, GRE, or decap-groups). It allows the switch to incorrectly process and forward unexpected tunneled packets if they match a configured decapsulation IP, without properly verifying the tunnel protocol type. As a result, traffic that was not intended for decapsulation can be accepted and handled, potentially leading to traffic misrouting or security bypass. The issue has also been reported as being actively exploited in the wild.
The second flaw added to the catalog, tracked as CVE-2026-11645, is an out-of-bounds memory access in the V8 JavaScript engine. Out-of-bounds memory access occurs when a program reads from or writes to a memory location outside the boundaries of an allocated buffer, array, or memory region. Such flaws could lead to denial of service conditions (application crashes), privilege escalation, ot remote code execution (RCE). This flaw is the fifth Chrome zero-day that is being exploited in the wild in 2026. As usual, Google did not share technical details about the attacks exploiting this vulnerability.
The third flaw added to the catalog, tracked as CVE-2026-20245, is a privilege escalation flaw in Cisco Catalyst SD-WAN Manager, the platform formerly known as SD-WAN vManage. An authenticated local attacker can trigger the vulnerability to run arbitrary commands as root. No patch is out, and no workaround exists. The mechanics are straightforward: bad input validation. Although the flaw requires netadmin privileges, attackers can obtain them using stolen credentials or by exploiting previously disclosed vulnerabilities such as CVE-2026-20182 and CVE-2026-20127.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerabilities by June 23, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/193464/security/u-s-cisa-adds-cisco-catalyst-sd-wan-arista-extensible-operating-system-eos-and-google-chromium-v8-flaws-to-its-known-exploited-vulnerabilities-catalog.html