CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation
CISA added three actively exploited flaws in Cisco, Chrome, and Arista products to its KEV catalog and ordered federal fixes by June 23.
Intelligence analysis by GPT-5.4 Mini

CISA flagged three vulnerabilities as under active exploitation: a Cisco Catalyst SD-WAN Manager bug, a Chrome V8 sandbox escape issue, and an Arista EOS tunnel traffic flaw. Arista says no patch is planned for its issue, so mitigations will matter most.
CISA found three broken locks that bad actors are already trying to open: one in Cisco gear, one in Chrome, and one in Arista switches. It is telling government agencies to fix or block them fast, like putting extra bars on a door that burglars already know how to open.
Analysis
What CISA added
CISA placed three vulnerabilities into its Known Exploited Vulnerabilities catalog after reports that they are being actively abused. The list covers Cisco Catalyst SD-WAN Manager, Google Chrome’s V8 engine, and Arista Extensible Operating System (EOS).
Cisco and Chrome
The Cisco issue, CVE-2026-20245, is an output-encoding problem in Catalyst SD-WAN Manager. According to the notice, an authenticated local attacker could use a crafted file to run commands as root.
The Chrome issue, CVE-2026-11645, affects V8 and involves an out-of-bounds read/write. CISA’s description says a remote attacker could use a crafted HTML page to execute code inside the browser sandbox.
Arista and the no-patch path
The Arista flaw, CVE-2026-7473, affects EOS when a device is configured as a tunnel endpoint. Arista says unexpected tunneled packets can be processed when the switch does not verify tunnel protocol type. The company says the flaw has been reported as exploited in the wild.
Arista also says no fix is planned because patching could break existing deployments. Instead, it recommends mitigations such as ACLs on upstream devices or on the affected devices themselves to allow legitimate tunnel traffic and block malicious traffic.
Operational impact
CISA ordered Federal Civilian Executive Branch agencies to apply fixes or mitigations by June 23, 2026. That deadline shows how seriously the government is treating the exposure, and it gives other defenders a clear signal that these issues should be addressed immediately rather than deferred.
Key points
- CISA added three vulnerabilities to its KEV catalog after reports of active exploitation.
- The catalog entries cover Cisco Catalyst SD-WAN Manager, Google Chrome V8, and Arista EOS.
- Arista says no patch is planned for CVE-2026-7473 and recommends ACL-based mitigations.
- Federal civilian agencies must apply fixes or mitigations by June 23, 2026.
- The Chrome flaw could let a remote attacker execute code inside the browser sandbox.
The KEV listing pushes defenders to act quickly, which can reduce the window attackers have to keep abusing these flaws. For Arista, the published mitigations give operators a path to reduce risk even without a patch.
If organizations delay patching or mitigation, attackers may continue using these vulnerabilities against exposed Cisco, Chrome, and Arista systems. The Arista case is especially risky because no patch is planned, so weak ACL coverage or misconfiguration could leave affected networks open.



