CISA Expands Active Exploit Catalog with Cisco, Arista, and Chromium Flaws
ID: 3962f3fb-09a8-5ed5-afb9-864186ed9407
STIX ID: report--3962f3fb-09a8-5ed5-afb9-864186ed9407
Feed Name: securityonline.info
Threat Score
CISA updated its active exploit catalog to include three weaponized vulnerabilities—CVE-2026-20245 (Cisco Catalyst SD‑WAN Manager command injection allowing root escalation), CVE-2026-11645 (Chromium V8 out-of-bounds RCE via malicious HTML), and CVE-2026-7473 (Arista EOS tunnel decapsulation allowing unexpected packet forwarding)—and warns of observed limited real-world exploitation; administrators are urged to apply vendor hotfixes immediately and monitor perimeter logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
