Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Highlights Cisco, Chrome, Arista Security Flaws

CISA Highlights Cisco, Chrome, Arista Security Flaws

Posted on June 13, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently expanded its Known Exploited Vulnerabilities (KEV) catalog by including three new security flaws. This update, announced on Tuesday, comes in response to confirmed reports of these vulnerabilities being actively exploited.

Details of the Newly Identified Flaws

The vulnerabilities added to the KEV catalog are significant due to their potential impact. The first flaw, CVE-2026-20245, affects the Cisco Catalyst SD-WAN Manager. It involves improper encoding or escaping of output, which could be exploited by an authenticated local attacker to execute commands as root by using a specially crafted file.

The second vulnerability, CVE-2026-11645, is found in Google Chrome’s V8 engine. This out-of-bounds read and write issue allows remote attackers to run arbitrary code within a sandbox environment using a crafted HTML page.

The third flaw, CVE-2026-7473, pertains to the Arista Extensible Operating System (EOS). It involves an incomplete comparison leading to potential processing of unauthorized tunnel traffic, which can be exploited on certain configurations.

Arista’s Approach to Unpatched Vulnerability

Arista Networks has acknowledged the exploitation of CVE-2026-7473 in the wild, specifically impacting its 7020R, 7280R/R2, and 7500R/R2 series devices. The vulnerability can be triggered on devices configured as tunnel endpoints, such as those using VXLAN or GRE interfaces.

Despite its severity, Arista has decided against issuing a patch, citing possible disruptions to existing configurations. Instead, the company recommends two mitigation strategies: implementing access control lists (ACLs) on upstream devices or directly on affected devices to filter legitimate from malicious traffic.

Urgent Mitigation Measures for Federal Agencies

In light of these vulnerabilities, CISA has mandated Federal Civilian Executive Branch (FCEB) agencies to apply the necessary patches or mitigation strategies by June 23, 2026. This directive aims to safeguard critical infrastructure and reduce the risk of exploitation.

The inclusion of these vulnerabilities in the KEV catalog underscores the importance of proactive cybersecurity measures and the need for organizations to stay vigilant against emerging threats.

Moving forward, it is crucial for entities using affected systems to heed CISA’s guidance and take immediate action to bolster their cybersecurity defenses.

The Hacker News Tags:Arista, Chrome, CISA, Cisco, CVE, Cybersecurity, Exploit, network security, security patch, Vulnerabilities

Post navigation

Previous Post: Langflow Security Flaw Enables Unauthenticated Access
Next Post: Uncover Gaps in Automated Pentesting with Expert Insights

Related Posts

MuddyWater Deploys UDPGangster Backdoor in Targeted Turkey-Israel-Azerbaijan Campaign MuddyWater Deploys UDPGangster Backdoor in Targeted Turkey-Israel-Azerbaijan Campaign The Hacker News
EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations The Hacker News
Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware The Hacker News
New Fluent Bit Flaws Expose Cloud to RCE and Stealthy Infrastructure Intrusions New Fluent Bit Flaws Expose Cloud to RCE and Stealthy Infrastructure Intrusions The Hacker News
RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers The Hacker News
Security Flaws in NodeBB Highlight Admin Access Risks Security Flaws in NodeBB Highlight Admin Access Risks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Chrome Extension Secretly Collects AI Interactions
  • Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks
  • Critical Security Update for JetBrains TeamCity Users
  • AI Uncovers Cryptographic Flaws Overlooked by Experts
  • Claude AI Unveils Breakthrough in Cryptanalysis

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Chrome Extension Secretly Collects AI Interactions
  • Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks
  • Critical Security Update for JetBrains TeamCity Users
  • AI Uncovers Cryptographic Flaws Overlooked by Experts
  • Claude AI Unveils Breakthrough in Cryptanalysis

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark