securityaffairs.com 6/10/2026, 11:28:24 AM · external

CISA flags Arista, Chrome, Cisco flaws; patch by June 23

CISA flags Arista, Chrome, Cisco flaws; patch by June 23
Developing story vulnerability 4 articles tracked
CISA adds Cisco, Arista and Chrome flaws to KEV list
CyberSIXT Evidence Panel

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three significant vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. These include:

1. **CVE-2026-7473**: A flaw in the Arista Extensible Operating System which may allow unauthorized traffic processing, leading to potential security bypass.

2. **CVE-2026-11645**: An out-of-bounds read/write vulnerability in Google Chromium's V8 engine, potentially allowing Denial of Service and remote code execution.

3. **CVE-2026-20245**: A privilege escalation issue in Cisco Catalyst SD-WAN Manager that enables local authenticated attackers to execute commands as root.

CISA mandates federal agencies to address these vulnerabilities by June 23, 2026, advising private organizations to also review these vulnerabilities.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline