Security Affairs newsletter Round 583 by Pierluigi Paganini – INTERNATIONAL EDITION
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20245 | Command Injection as Root in Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) contains an improper encoding or escaping of output flaw (CWE-116) in its handling of user-supplied files. An attacker who already has authenticated access to the system can trigger it by supplying a crafted file, because the file's contents are not properly escaped before being processed. Successful exploitation yields arbitrary command execution with root privileges, giving the attacker full control of the SD-WAN management platform. Organizations running Cisco Catalyst SD-WAN Manager/vManage to manage their SD-WAN fabric are affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-09, indicating active exploitation, though no public proof-of-concept is known and ransomware use has not been confirmed. Do: Apply the fixed release per Cisco's security advisory (specific fixed versions are not included in the available data), and prioritize this patch given the KEV listing. Because the flaw requires authenticated local access, restrict management-plane access to trusted administrators and networks, review privileged accounts on the manager, and audit the system for unexpected processes or changes. Federal agencies must follow the KEV required action under BOD 22-01 (mitigate per vendor instructions or discontinue use). | 7.8 | 25% | KEV |
| largeon the order of tens of thousands of deployments worldwide | |
| CVE-2026-20971 | Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code. Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code. NVD description · AI analysis pending | 7.3 | <1% |
| — | ||
| CVE-2026-43503 | In the Linux kernel, the following vulnerability has been resolved: In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when moving frags from source to destination. __pskb_copy_fclone() defers the rest of the shinfo metadata to skb_copy_header() after copying frag descriptors, but that helper only carries over gso_{size,segs, type} and never touches skb_shinfo()->flags; skb_shift() moves frag descriptors directly and leaves flags untouched. As a result, the destination skb keeps a reference to the same externally-owned or page-cache-backed pages while reporting skb_has_shared_frag() as false. The mismatch is harmful in any in-place writer that uses skb_has_shared_frag() to decide whether shared pages must be detoured through skb_cow_data(). ESP input is one such writer (esp4.c, esp6.c), and a single nft 'dup to ' rule -- or any other nf_dup_ipv4() / xt_TEE caller -- is enough to land a pskb_copy()'d skb in esp_input() with the marker stripped, letting an unprivileged user write into the page cache of a root-owned read-only file via authencesn-ESN stray writes. Set SKBFL_SHARED_FRAG on the destination whenever frag descriptors were actually moved from the source. skb_copy() and skb_copy_expand() share skb_copy_header() too but linearize all paged data into freshly allocated head storage and emerge with nr_frags == 0, so skb_has_shared_frag() returns false on its own; they need no change. The same omission exists in skb_gro_receive() and skb_gro_receive_list(). The former moves the incoming skb's frag descriptors into the accumulator's last sub-skb via two paths (a direct frag-move loop and the head_frag + memcpy path); the latter chains the incoming skb whole onto p's frag_list. Downstream skb_segment() reads only skb_shinfo(p)->flags, and skb_segment_list() reuses each sub-skb's shinfo as the nskb -- both p and lp must carry the marker. The same omission also exists in tcp_clone_payload(), which builds an MTU probe skb by moving frag descriptors from skbs on sk_write_queue into a freshly allocated nskb. The helper falls into the same family and warrants the same fix for consistency; no TCP TX-side in-place writer is currently known to reach a user page through this gap, but a future consumer depending on the marker would regress silently. The same omission exists in skb_segment(): the per-iteration flag merge takes only head_skb's flag, and the inner switch that rebinds frag_skb to list_skb on head_skb-frags exhaustion does not fold the new frag_skb's flag into nskb. Fold frag_skb's flag at both sites so segments drawing frags from frag_list members carry the marker. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2026-47729 | Squid is a caching proxy for the Web. Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6. NVD description · AI analysis pending | 6.5 | 2% |
| — |
Full article535 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
The Broker Behind FortiBleed: Anatomy of a Russian-Speaking Access Operation
Security News This Week: Hackers Claim to Leak Stolen Madison Square Garden Data
Scaling cybercrime disruption through innovation and AI
Global cyber strike disrupts SocGholish, Amadey, and StealC malware networks
Third Defendant Sentenced To Prison For Hacking Fantasy Sports And Betting Website
India’s Tata Electronics hit by cyber breach claiming to expose Apple, Tesla trade secrets
Polymarket to Refund Users After Hackers Steal $3M in Frontend Attack
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access
Malware
A VBScript campaign distributed through WhatsApp deploying RMM software
Prinz Eugen ransomware: a deep dive into a new Go-based encryptor
Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker
Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem
Hacking
Squidbleed (CVE-2026-47729) Heartbleed’s ancient cousin, hiding in Squid since 1997
When Defenses Become Attack Surface: CVE-2026-20971, a Samsung Kernel UAF
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager
AISLE Discovers 6 New CVEs in curl, Including the Oldest Issue Ever Reported
A new unpatchable flaw in Apple chips opens the door to an iPhone jailbreak
Elite network says it was hacked after members’ personal data was left exposed
New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries
Dissecting and Exploiting Linux LPE Variant: DirtyClone (CVE-2026-43503)
Intelligence and Information Warfare
Claude Fable 5 Resurfaces in Android App as NSA Breach Testimony Reshapes Ban
From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet
Five Eyes cyber security agencies statement The AI shift in cyber risk: why leaders must act now
Weaponized AI: Inside The Criminal Ecosystem Fueling The Fifth Wave of Cybercrime
macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox
Russia Breaks Into Human Rights Activist’s Phone With Cellebrite
CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure
Russian Intelligence Services Continue to Target Commercial Messaging Applications
Cybersecurity
Deutsche Bahn halts trains nationwide amid IT meltdown
How to Disappear From the Internet in 7 Days
The quantum threat: Navigating cryptographic risks in a new computing era
Dozens of America’s largest companies have no simple way to report security flaws
Xsolis Data Breach Affects 1.4 Million Individuals
‘Wake-up call’: Europe reacts to Anthropic halting access to its Fable 5 and Mythos 5 AI models
Meta Pauses Employee-Tracking Program Following Internal Data Leak
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
you might also like
leave a comment
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/194372/security/security-affairs-newsletter-round-583-by-pierluigi-paganini-international-edition.html