CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation

CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation — Cybersecurity | Versia.media

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on Tuesday, based on evidence of active exploitation.

The identified vulnerabilities are as follows:

CVE-2026-20245 (CVSS score: 7.8) – An improper output encoding or escaping flaw in Cisco Catalyst SD-WAN Manager, enabling an authenticated, local attacker to run arbitrary commands as root by providing a crafted file to the impacted system.

CVE-2026-11645 (CVSS score: 8.8) – An out-of-bounds read and write vulnerability in Google Chrome V8, allowing a remote attacker to execute arbitrary code within a sandbox using a specially crafted HTML page.

CVE-2026-7473 (CVSS score: 6.9) – An incomplete comparison with missing factors vulnerability in Arista Extensible Operating System (EOS), which could be exploited to process non-configured tunnel traffic.

No Patch Planned for Exploited Arista EOS Flaw

"On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packets with a destination IP matching its configured decapsulation IP," Arista stated.

"This happens because the switch does not verify the tunnel protocol type, potentially leading to the unintended processing of non-configured tunnel traffic."

The security issue primarily affects 7020R, 7280R/R2, and 7500R/R2 series products. However, for successful exploitation, the device must be set up as a tunnel endpoint with a decapsulation IP, such as a VXLAN VTEP, a GRE tunnel endpoint, or with an IP decap-group.

The network equipment manufacturer acknowledged that the vulnerability has been "reported as being exploited in the wild," crediting Comcast's Scott Christiansen, Lukas Peitz, Rich Compton, and Jonathan Davis for responsible disclosure.

Despite this, Arista indicated that no patches are planned for CVE-2026-7473, citing risks that such fixes could disrupt existing configurations in deployments. The company has provided mitigations to address the issue.

"There are two broad approaches to mitigate this issue—(1) applying ACLs on upstream devices or (2) applying ACLs on the devices where the unexpected decapsulation is happening," Arista said. "In both cases, the idea is to either selectively allow only legitimate tunnel traffic or to selectively block malicious tunnel traffic."

Federal Civilian Executive Branch (FCEB) agencies have been directed to apply the necessary fixes or mitigations by June 23, 2026, to counter the threat posed by these three vulnerabilities.

← Cybersecurity