discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation

CISA added three actively exploited flaws in Cisco, Chrome, and Arista products to its KEV catalog and ordered federal fixes by June 23.

By Ravie Lakshmanan·Jun 10·thehackernews.com·2 min read

Intelligence analysis by GPT-5.4 Mini

CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation
Image: thehackernews.com

CISA flagged three vulnerabilities as under active exploitation: a Cisco Catalyst SD-WAN Manager bug, a Chrome V8 sandbox escape issue, and an Arista EOS tunnel traffic flaw. Arista says no patch is planned for its issue, so mitigations will matter most.

Why it matters

KEV additions are a strong signal that attackers are already using these bugs in the real world. For defenders, this raises the priority of patching, hardening, or mitigating affected Cisco, Chrome, and Arista systems fast.

CISA found three broken locks that bad actors are already trying to open: one in Cisco gear, one in Chrome, and one in Arista switches. It is telling government agencies to fix or block them fast, like putting extra bars on a door that burglars already know how to open.

Analysis

What CISA added

CISA placed three vulnerabilities into its Known Exploited Vulnerabilities catalog after reports that they are being actively abused. The list covers Cisco Catalyst SD-WAN Manager, Google Chrome’s V8 engine, and Arista Extensible Operating System (EOS).

Cisco and Chrome

The Cisco issue, CVE-2026-20245, is an output-encoding problem in Catalyst SD-WAN Manager. According to the notice, an authenticated local attacker could use a crafted file to run commands as root.

The Chrome issue, CVE-2026-11645, affects V8 and involves an out-of-bounds read/write. CISA’s description says a remote attacker could use a crafted HTML page to execute code inside the browser sandbox.

Arista and the no-patch path

The Arista flaw, CVE-2026-7473, affects EOS when a device is configured as a tunnel endpoint. Arista says unexpected tunneled packets can be processed when the switch does not verify tunnel protocol type. The company says the flaw has been reported as exploited in the wild.

Arista also says no fix is planned because patching could break existing deployments. Instead, it recommends mitigations such as ACLs on upstream devices or on the affected devices themselves to allow legitimate tunnel traffic and block malicious traffic.

Operational impact

CISA ordered Federal Civilian Executive Branch agencies to apply fixes or mitigations by June 23, 2026. That deadline shows how seriously the government is treating the exposure, and it gives other defenders a clear signal that these issues should be addressed immediately rather than deferred.

Key points

  • CISA added three vulnerabilities to its KEV catalog after reports of active exploitation.
  • The catalog entries cover Cisco Catalyst SD-WAN Manager, Google Chrome V8, and Arista EOS.
  • Arista says no patch is planned for CVE-2026-7473 and recommends ACL-based mitigations.
  • Federal civilian agencies must apply fixes or mitigations by June 23, 2026.
  • The Chrome flaw could let a remote attacker execute code inside the browser sandbox.
The Upside

The KEV listing pushes defenders to act quickly, which can reduce the window attackers have to keep abusing these flaws. For Arista, the published mitigations give operators a path to reduce risk even without a patch.

The Downside

If organizations delay patching or mitigation, attackers may continue using these vulnerabilities against exposed Cisco, Chrome, and Arista systems. The Arista case is especially risky because no patch is planned, so weak ACL coverage or misconfiguration could leave affected networks open.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritypolicyregulationtechunited-states

Author

Ravie Lakshmanan

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 10, 2026

Source

thehackernews.com

Share

Topics

securitypolicyregulationtechunited-states

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…