# CISA Adds Chrome, Cisco, and Arista Flaws to Active Exploitation List—Arista Refuses to Patch


The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three newly discovered vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, marking each as actively exploited in the wild. The additions underscore an escalating threat landscape affecting critical infrastructure, enterprise networks, and consumer endpoints—with one vendor notably refusing to release a patch.


## The Threat


The three vulnerabilities target fundamentally different attack surfaces but share a common characteristic: attackers are already weaponizing them. The most critical is CVE-2026-11645 in Google Chrome's V8 JavaScript engine, which allows remote code execution through a specially crafted HTML page. This attack requires no user authentication and reaches users at massive scale through drive-by download tactics or malicious websites. The vulnerability bypasses Chrome's sandbox protections, providing attackers with arbitrary code execution within a user's browser session.


CVE-2026-20245 targets Cisco Catalyst SD-WAN Manager, a critical network appliance used by enterprises to manage distributed wide-area networks. This vulnerability exploits improper output encoding, allowing authenticated local attackers to execute arbitrary commands with root privileges. In SD-WAN deployments, compromised manager instances can lead to network-wide attacks, lateral movement, and access to connected branch offices and data centers.


The third flaw, CVE-2026-7473 in Arista Extensible Operating System (EOS), reveals a subtle but dangerous logic error in how network switches process tunneled traffic. The vulnerability allows switches configured as tunnel endpoints to incorrectly decapsulate and forward packets that don't belong to configured tunnel protocols. The practical impact: an attacker can inject arbitrary tunneled packets into a network and have them processed as legitimate traffic, potentially bypassing security controls and network segmentation.


What makes this trio particularly concerning is not just their severity, but the admission from all three vendors that exploitation is actively occurring in production environments.


## Severity and Impact


| Aspect | Details |

|--------|---------|

| CVE-2026-20245 (Cisco) | CVSS 7.8 (High) |

| CVE-2026-11645 (Chrome) | CVSS 8.8 (Critical) |

| CVE-2026-7473 (Arista) | CVSS 6.9 (Medium-High) |

| Attack Vector | Network (Chrome), Local (Cisco), Adjacent Network (Arista) |

| Authentication Required | Chrome: None; Cisco: Required (local); Arista: None |

| User Interaction | Chrome: Required; Cisco: None; Arista: None |

| Privilege Impact | All three allow privilege escalation or security control bypass |

| CISA Deadline | Federal agencies must remediate by June 23, 2026 |


## Affected Products


Google Chrome (CVE-2026-11645)

  • All versions prior to the latest security patch
  • Impact: Windows, macOS, Linux desktop users; enterprise Chromebook fleets
  • Chrome OS devices are also affected if running vulnerable V8 versions

  • Cisco Catalyst SD-WAN Manager (CVE-2026-20245)

  • Organizations running any non-patched version of Manager
  • Requires authenticated local access (administrators, services running locally)
  • Affects SD-WAN fabric security and trust model

  • Arista EOS (CVE-2026-7473)

  • Series: 7020R, 7280R, 7280R2, 7500R, 7500R2
  • Requires: Device configured as tunnel endpoint with decapsulation enabled (VXLAN VTEP, GRE tunnel endpoint, or IP decap-group)
  • Impact primarily in: Data center, campus, and service provider networks using overlay protocols

  • ## Mitigations


    For Chrome (CVE-2026-11645):

  • Update immediately to the latest version via Settings > About Google Chrome (auto-update)
  • Enterprise deployments should force updates via management policy
  • Users should disable untrusted websites and avoid clicking suspicious links while patches roll out
  • Cloud-based threat prevention solutions can block malicious HTML payloads at the gateway

  • For Cisco SD-WAN Manager (CVE-2026-20245):

  • Apply Cisco's published security patches immediately
  • Restrict local access to Manager instances to trusted administrator accounts
  • Implement network segmentation to limit who can reach Manager APIs
  • Review access logs for unauthorized authentication attempts

  • For Arista EOS (CVE-2026-7473):

    This is where the mitigation story becomes complicated. Arista has announced it will not release a patch, citing concerns that fixing the tunnel processing logic could break existing customer configurations. Instead, the company recommends:

  • Implement Access Control Lists (ACLs) on upstream devices to restrict tunnel traffic to only legitimate sources
  • Apply ACLs on the affected Arista devices themselves to block unexpected tunneled packets
  • Disable tunnel decapsulation on interfaces that don't require it
  • Monitor tunnel traffic for anomalous patterns

  • Network operators should test ACL-based mitigations in lab environments before production deployment, as incorrect configuration could impact legitimate tunnel traffic.


    ## References


  • CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • Cisco Security Advisory CVE-2026-20245: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/
  • Google Chrome Security Release: https://chromereleases.googleblog.com/
  • Arista Security Advisory CVE-2026-7473: https://www.arista.com/en/support/advisories
  • CISA/NSA Alert on Federal Deadline: https://www.cisa.gov/

  • ## HackWire Analysis


    The Arista decision to forego patching represents a troubling but increasingly common dilemma in enterprise security: the tension between fixing known vulnerabilities and maintaining system stability. Arista's rationale—that a patch could break existing tunnel configurations—reflects a real concern in large deployments where configuration drift is endemic. Yet it also represents a capitulation to operational inertia that puts customers at demonstrable risk.


    What's particularly striking is that Arista has *confirmed active exploitation in the wild* while simultaneously refusing to patch. This places the burden entirely on customers to implement defensive ACLs, which requires both security expertise and network visibility that many organizations lack. In complex multi-vendor network environments, the ACL-based mitigation may be incomplete or create unexpected traffic filtering.


    The Chrome and Cisco flaws are more straightforward: apply patches and move on. But the Chrome V8 vulnerability's critical CVSS score (8.8) and ease of weaponization through drive-by downloads should prioritize it above other patching schedules. Enterprise security teams should treat this like a critical ransomware-adjacent threat—aggressive rollout timelines, not standard patch cycles.


    The federal deadline of June 23 is only two weeks away. Agencies running any of these three products are likely scrambling, particularly those with Arista switches in tunnel-heavy environments (data centers, cloud interconnects). This creates a secondary risk: rushed, poorly tested mitigations that introduce their own security gaps.


    The broader pattern here is worth noting: network infrastructure (Cisco, Arista) and browser engines (Chrome) remain top-tier attack targets because they sit at traffic chokepoints. A compromised Arista switch or Cisco manager can affect thousands of downstream users. A Chrome zero-day reaches millions instantly. These high-value targets will continue to attract skilled attackers, and vendors' willingness to patch expeditiously—or lack thereof—should factor into procurement decisions.


    — *HackWire Editorial*


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)