# CISA Adds Chrome, Cisco, and Arista Flaws to Active Exploitation List—Arista Refuses to Patch
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three newly discovered vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, marking each as actively exploited in the wild. The additions underscore an escalating threat landscape affecting critical infrastructure, enterprise networks, and consumer endpoints—with one vendor notably refusing to release a patch.
## The Threat
The three vulnerabilities target fundamentally different attack surfaces but share a common characteristic: attackers are already weaponizing them. The most critical is CVE-2026-11645 in Google Chrome's V8 JavaScript engine, which allows remote code execution through a specially crafted HTML page. This attack requires no user authentication and reaches users at massive scale through drive-by download tactics or malicious websites. The vulnerability bypasses Chrome's sandbox protections, providing attackers with arbitrary code execution within a user's browser session.
CVE-2026-20245 targets Cisco Catalyst SD-WAN Manager, a critical network appliance used by enterprises to manage distributed wide-area networks. This vulnerability exploits improper output encoding, allowing authenticated local attackers to execute arbitrary commands with root privileges. In SD-WAN deployments, compromised manager instances can lead to network-wide attacks, lateral movement, and access to connected branch offices and data centers.
The third flaw, CVE-2026-7473 in Arista Extensible Operating System (EOS), reveals a subtle but dangerous logic error in how network switches process tunneled traffic. The vulnerability allows switches configured as tunnel endpoints to incorrectly decapsulate and forward packets that don't belong to configured tunnel protocols. The practical impact: an attacker can inject arbitrary tunneled packets into a network and have them processed as legitimate traffic, potentially bypassing security controls and network segmentation.
What makes this trio particularly concerning is not just their severity, but the admission from all three vendors that exploitation is actively occurring in production environments.
## Severity and Impact
| Aspect | Details |
|--------|---------|
| CVE-2026-20245 (Cisco) | CVSS 7.8 (High) |
| CVE-2026-11645 (Chrome) | CVSS 8.8 (Critical) |
| CVE-2026-7473 (Arista) | CVSS 6.9 (Medium-High) |
| Attack Vector | Network (Chrome), Local (Cisco), Adjacent Network (Arista) |
| Authentication Required | Chrome: None; Cisco: Required (local); Arista: None |
| User Interaction | Chrome: Required; Cisco: None; Arista: None |
| Privilege Impact | All three allow privilege escalation or security control bypass |
| CISA Deadline | Federal agencies must remediate by June 23, 2026 |
## Affected Products
Google Chrome (CVE-2026-11645)
Cisco Catalyst SD-WAN Manager (CVE-2026-20245)
Arista EOS (CVE-2026-7473)
## Mitigations
For Chrome (CVE-2026-11645):
For Cisco SD-WAN Manager (CVE-2026-20245):
For Arista EOS (CVE-2026-7473):
This is where the mitigation story becomes complicated. Arista has announced it will not release a patch, citing concerns that fixing the tunnel processing logic could break existing customer configurations. Instead, the company recommends:
Network operators should test ACL-based mitigations in lab environments before production deployment, as incorrect configuration could impact legitimate tunnel traffic.
## References
## HackWire Analysis
The Arista decision to forego patching represents a troubling but increasingly common dilemma in enterprise security: the tension between fixing known vulnerabilities and maintaining system stability. Arista's rationale—that a patch could break existing tunnel configurations—reflects a real concern in large deployments where configuration drift is endemic. Yet it also represents a capitulation to operational inertia that puts customers at demonstrable risk.
What's particularly striking is that Arista has *confirmed active exploitation in the wild* while simultaneously refusing to patch. This places the burden entirely on customers to implement defensive ACLs, which requires both security expertise and network visibility that many organizations lack. In complex multi-vendor network environments, the ACL-based mitigation may be incomplete or create unexpected traffic filtering.
The Chrome and Cisco flaws are more straightforward: apply patches and move on. But the Chrome V8 vulnerability's critical CVSS score (8.8) and ease of weaponization through drive-by downloads should prioritize it above other patching schedules. Enterprise security teams should treat this like a critical ransomware-adjacent threat—aggressive rollout timelines, not standard patch cycles.
The federal deadline of June 23 is only two weeks away. Agencies running any of these three products are likely scrambling, particularly those with Arista switches in tunnel-heavy environments (data centers, cloud interconnects). This creates a secondary risk: rushed, poorly tested mitigations that introduce their own security gaps.
The broader pattern here is worth noting: network infrastructure (Cisco, Arista) and browser engines (Chrome) remain top-tier attack targets because they sit at traffic chokepoints. A compromised Arista switch or Cisco manager can affect thousands of downstream users. A Chrome zero-day reaches millions instantly. These high-value targets will continue to attract skilled attackers, and vendors' willingness to patch expeditiously—or lack thereof—should factor into procurement decisions.
— *HackWire Editorial*
## Related Coverage