Executive Summary
On June 10, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. These include CVE-2026-20245, an improper encoding vulnerability in Cisco Catalyst SD-WAN Manager; CVE-2026-11645, an out-of-bounds read and write flaw in Google Chrome's V8 engine; and CVE-2026-7473, an incomplete comparison vulnerability in Arista's Extensible Operating System (EOS). These vulnerabilities could allow attackers to execute arbitrary code or process unauthorized tunnel traffic, posing significant risks to affected systems.
The inclusion of these vulnerabilities in the KEV catalog underscores the persistent threat posed by actively exploited flaws in widely used software and hardware. Organizations are urged to apply the necessary patches or mitigations promptly to safeguard their systems against potential attacks.
Why This Matters Now
The active exploitation of these vulnerabilities highlights the immediate need for organizations to assess their exposure and implement recommended security measures to prevent potential breaches.
Attack Path Analysis
An attacker exploited CVE-2026-20245 in Cisco Catalyst SD-WAN Manager by uploading a crafted file, achieving root access. They then escalated privileges to root, enabling full control over the system. Utilizing this access, the attacker moved laterally to other systems within the SD-WAN environment. They established a command and control channel to maintain persistent access. Sensitive data was exfiltrated from the compromised systems. Finally, the attacker pushed unauthorized configuration changes to edge devices, disrupting network operations.
Kill Chain Progression
Initial Compromise
Description
An attacker exploited CVE-2026-20245 in Cisco Catalyst SD-WAN Manager by uploading a crafted file, achieving root access.
Related CVEs
CVE-2026-20245
CVSS 7.8An improper encoding or escaping of output vulnerability in Cisco Catalyst SD-WAN Manager allows an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.
Affected Products:
Cisco Catalyst SD-WAN Manager – All versions prior to the fixed release
Exploit Status:
exploited in the wildCVE-2026-11645
CVSS 8.8An out-of-bounds read and write vulnerability in Google Chrome V8 allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Affected Products:
Google Chrome – All versions prior to the fixed release
Exploit Status:
exploited in the wildCVE-2026-7473
CVSS 5.8An incomplete comparison with missing factors vulnerability in Arista Extensible Operating System (EOS) could be exploited to process non-configured tunnel traffic.
Affected Products:
Arista Extensible Operating System (EOS) – 7020R, 7280R/R2, 7500R/R2 series
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter
Valid Accounts
Account Discovery
Network Service Scanning
Remote Services
Impair Defenses
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Critical exposure through SD-WAN infrastructure vulnerabilities enabling lateral movement, command & control establishment, and potential data exfiltration across network segments.
Financial Services
High-risk vulnerability exploitation threatens encrypted traffic security, zero trust segmentation controls, and regulatory compliance for PCI/HIPAA data protection requirements.
Health Care / Life Sciences
SD-WAN Manager flaws compromise patient data encryption, east-west traffic security, and HIPAA compliance controls for healthcare network infrastructure protection.
Government Administration
Active exploitation of Cisco vulnerabilities threatens government network segmentation, encrypted communications, and critical infrastructure requiring immediate CISA KEV remediation.
Sources
- CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitationhttps://thehackernews.com/2026/06/cisa-adds-cisco-chrome-and-arista-flaws.htmlVerified
- CISA Adds One Known Exploited Vulnerability to Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- CVE-2026-20245 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2026-20245Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access may have been limited to the compromised workload, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: Even with root access, the attacker's ability to interact with other workloads would likely have been constrained.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement could have been restricted, limiting their ability to compromise additional systems.
Control: Multicloud Visibility & Control
Mitigation: Establishing and maintaining command and control channels may have been hindered, reducing the attacker's persistence.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely have been identified and blocked, protecting sensitive information.
The attacker's ability to alter configurations and disrupt operations may have been limited, reducing operational impact.
Impact at a Glance
Affected Business Functions
- Network Management
- Web Browsing
- Data Transmission
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive network configurations and user data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the SD-WAN environment.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts of known vulnerabilities.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to unauthorized activities promptly.
- • Apply Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing data exfiltration.
- • Regularly update and patch systems to mitigate known vulnerabilities and reduce the attack surface.



