Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Highlights Cisco, Chrome, Arista Security Flaws

CISA Highlights Cisco, Chrome, Arista Security Flaws

Posted on June 13, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently expanded its Known Exploited Vulnerabilities (KEV) catalog by including three new security flaws. This update, announced on Tuesday, comes in response to confirmed reports of these vulnerabilities being actively exploited.

Details of the Newly Identified Flaws

The vulnerabilities added to the KEV catalog are significant due to their potential impact. The first flaw, CVE-2026-20245, affects the Cisco Catalyst SD-WAN Manager. It involves improper encoding or escaping of output, which could be exploited by an authenticated local attacker to execute commands as root by using a specially crafted file.

The second vulnerability, CVE-2026-11645, is found in Google Chrome’s V8 engine. This out-of-bounds read and write issue allows remote attackers to run arbitrary code within a sandbox environment using a crafted HTML page.

The third flaw, CVE-2026-7473, pertains to the Arista Extensible Operating System (EOS). It involves an incomplete comparison leading to potential processing of unauthorized tunnel traffic, which can be exploited on certain configurations.

Arista’s Approach to Unpatched Vulnerability

Arista Networks has acknowledged the exploitation of CVE-2026-7473 in the wild, specifically impacting its 7020R, 7280R/R2, and 7500R/R2 series devices. The vulnerability can be triggered on devices configured as tunnel endpoints, such as those using VXLAN or GRE interfaces.

Despite its severity, Arista has decided against issuing a patch, citing possible disruptions to existing configurations. Instead, the company recommends two mitigation strategies: implementing access control lists (ACLs) on upstream devices or directly on affected devices to filter legitimate from malicious traffic.

Urgent Mitigation Measures for Federal Agencies

In light of these vulnerabilities, CISA has mandated Federal Civilian Executive Branch (FCEB) agencies to apply the necessary patches or mitigation strategies by June 23, 2026. This directive aims to safeguard critical infrastructure and reduce the risk of exploitation.

The inclusion of these vulnerabilities in the KEV catalog underscores the importance of proactive cybersecurity measures and the need for organizations to stay vigilant against emerging threats.

Moving forward, it is crucial for entities using affected systems to heed CISA’s guidance and take immediate action to bolster their cybersecurity defenses.

The Hacker News Tags:Arista, Chrome, CISA, Cisco, CVE, Cybersecurity, Exploit, network security, security patch, Vulnerabilities

Post navigation

Previous Post: Langflow Security Flaw Enables Unauthenticated Access
Next Post: Uncover Gaps in Automated Pentesting with Expert Insights

Related Posts

Infostealer Attack via Docker Highlights Security Risks Infostealer Attack via Docker Highlights Security Risks The Hacker News
Microsoft Addresses Critical SharePoint Security Flaw Microsoft Addresses Critical SharePoint Security Flaw The Hacker News
How to Gain Control of AI Agents and Non-Human Identities How to Gain Control of AI Agents and Non-Human Identities The Hacker News
Android Malware Poses Threat to Mobile Banking Users Android Malware Poses Threat to Mobile Banking Users The Hacker News
Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access The Hacker News
CTEM’s Core: Prioritization and Validation CTEM’s Core: Prioritization and Validation The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Odyssey Stealer Targets macOS: Global Crypto Threat
  • Over 200 GitHub Repositories Exploit Malware Threat
  • Ransomware Negotiator Sentenced for BlackCat Involvement
  • Dormant GitHub Accounts Exploited for Source Code Recon
  • Sophisticated GigaWiper Malware Threatens System Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Odyssey Stealer Targets macOS: Global Crypto Threat
  • Over 200 GitHub Repositories Exploit Malware Threat
  • Ransomware Negotiator Sentenced for BlackCat Involvement
  • Dormant GitHub Accounts Exploited for Source Code Recon
  • Sophisticated GigaWiper Malware Threatens System Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark