Close Menu
    What's Hot

    I Sold My Business for $280M: Advice for Young Entrepreneurs

    A Meta Employee Who Just Lost Their Job Was Detained by Immigration Agents

    Oil tankers increase ‘dark’ transits through Strait of Hormuz

    Facebook X (Twitter) Instagram
    Trending
    • I Sold My Business for $280M: Advice for Young Entrepreneurs
    • A Meta Employee Who Just Lost Their Job Was Detained by Immigration Agents
    • Oil tankers increase ‘dark’ transits through Strait of Hormuz
    • Ingersoll Rand Inc. (IR) Presents at 16th Annual Wells Fargo Industrials & Materials Conference Transcript
    • England 3 – 0 Costa Rica
    • Trump Muses About Government Taking a Piece of A.I. Companies
    • Democrats Try to Move Past ‘Cultural Pandering’ to Latinos for Midterm Elections
    • Ronaldo misses big chances in Portugal’s World Cup warmup win over Nigeria | World Cup 2026 News
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation

    adminBy adminJune 10, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 10, 2026Vulnerability / Network Security

    CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation.

    The list of vulnerabilities is as follows –

    • CVE-2026-20245 (CVSS score: 7.8) – An improper encoding or escaping of output vulnerability in Cisco Catalyst SD-WAN Manager that could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.
    • CVE-2026-11645 (CVSS score: 8.8) – An out-of-bounds read and write vulnerability in Google Chrome V8 that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
    • CVE-2026-7473 (CVSS score: 6.9) – An incomplete comparison with missing factors vulnerability in Arista Extensible Operating System (EOS) that could be exploited to process non-configured tunnel traffic.

    No Patch Planned for Exploited Arista EOS Flaw

    “On affected platforms running Arista EOS where a tunnel decapsulation configuration – such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface – is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packets with a destination IP matching its configured decapsulation IP,” Arista said.

    “This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic.”

    Cybersecurity

    The security defect mainly impacts 7020R, 7280R/R2, and 7500R/R2 series products. However, for successful exploitation to occur, the device must be configured as a tunnel endpoint with a decapsulation IP, such as a VXLAN VTEP, a GRE tunnel endpoint, or with an IP decap-group.

    The network equipment company acknowledged that the vulnerability has been “reported as being exploited in the wild,” crediting Comcast’s Scott Christiansen, Lukas Peitz, Rich Compton, and Jonathan Davis for responsibly disclosing it.

    Despite this, Arista said no patches are being planned to address CVE-2026-7473, citing risks that doing so could break existing configurations on deployments. The company has outlined mitigations to address the issue.

    “There are two broad approaches to mitigate this issue – (1) applying ACLs on upstream devices or (2) applying ACLs on the devices where the unexpected decapsulation is happening,” Arista said. “In both cases, the idea is to either selectively allow only legitimate tunnel traffic or to selectively block malicious tunnel traffic.”

    Federal Civilian Executive Branch (FCEB) agencies have been ordered to apply the necessary fixes or mitigations by June 23, 2026, to counter the threat posed by the three vulnerabilities.

    active adds Arista catalog Chrome CISA Cisco Exploitation Flaws KEV
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleAmtrak Speeds Up Trip From Vancouver to Seattle for World Cup Fans
    Next Article Nearly a million passports and photo IDs were left unprotected on the public internet
    admin
    • Website

    Related Posts

    CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats

    June 10, 2026

    Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE

    June 10, 2026

    China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

    June 10, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    I Sold My Business for $280M: Advice for Young Entrepreneurs

    A Meta Employee Who Just Lost Their Job Was Detained by Immigration Agents

    Oil tankers increase ‘dark’ transits through Strait of Hormuz

    Ingersoll Rand Inc. (IR) Presents at 16th Annual Wells Fargo Industrials & Materials Conference Transcript

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by