Executive Summary
On June 9, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation in the wild. The vulnerabilities include CVE-2026-7473 affecting Arista's Extensible Operating System, CVE-2026-11645 in Google Chromium's V8 engine, and CVE-2026-20245 in Cisco Catalyst SD-WAN Manager. These vulnerabilities pose significant risks to federal enterprises, as they are commonly targeted by malicious cyber actors.
The inclusion of these vulnerabilities in the KEV Catalog underscores the ongoing threat posed by unpatched software flaws. Organizations are urged to prioritize remediation efforts to mitigate potential exploitation and protect their networks against active threats.
Why This Matters Now
The addition of these vulnerabilities to the KEV Catalog highlights the immediate need for organizations to address these specific security flaws, as they are currently being exploited by threat actors, increasing the risk of cyberattacks.
Attack Path Analysis
An attacker exploited a vulnerability in the Arista EOS to gain unauthorized access to the network. They then escalated privileges by exploiting a Chrome V8 vulnerability on a compromised system. Using these elevated privileges, the attacker moved laterally across the network. They established command and control channels to maintain persistent access. Sensitive data was exfiltrated from the network. Finally, the attacker deployed ransomware, causing significant operational disruption.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited CVE-2026-7473 in Arista EOS to gain unauthorized access to the network.
Related CVEs
CVE-2026-7473
CVSS 5.8Arista EOS improperly decapsulates and forwards unexpected tunneled packets with a destination IP matching its configured decapsulation IP, potentially leading to unauthorized network access.
Affected Products:
Arista Networks EOS – All versions
Exploit Status:
exploited in the wildCVE-2026-11645
CVSS 8.8Out-of-bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Affected Products:
Google Chrome – < 149.0.7827.103
Exploit Status:
exploited in the wildCVE-2026-20245
CVSS 7.8A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager allows an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.
Affected Products:
Cisco Catalyst SD-WAN Manager – All versions
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploitation for Client Execution
Exploit Public-Facing Application
Application Layer Protocol
Exfiltration Over Alternative Protocol
External Remote Services
Hijack Execution Flow
Endpoint Denial of Service
Valid Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Access Controls and Identity Management
Control ID: 500.07
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Critical vulnerability management risks from Cisco SD-WAN and network infrastructure exploits threaten encrypted traffic security and zero trust segmentation capabilities.
Government Administration
FCEB agencies face mandatory remediation under BOD 22-01 for known exploited vulnerabilities affecting multicloud visibility and egress security enforcement.
Financial Services
Banking systems vulnerable to Chromium V8 exploits and lateral movement attacks requiring immediate PCI compliance and threat detection response measures.
Information Technology/IT
IT infrastructure providers exposed to Arista network equipment vulnerabilities impacting cloud native security fabric and Kubernetes security implementations.
Sources
- CISA Adds Three Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/06/09/cisa-adds-three-known-exploited-vulnerabilities-catalogVerified
- Arista Security Advisory 0137https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137Verified
- Stable Channel Update for Desktophttps://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.htmlVerified
- Cisco Security Advisory: Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerabilityhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzxVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely constrain the attacker's ability to move laterally and exfiltrate data, thereby reducing the overall blast radius.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial access may still occur, the attacker's ability to exploit this entry point to reach other systems would likely be constrained.
Control: Zero Trust Segmentation
Mitigation: Even with escalated privileges, the attacker's access to other systems would likely be limited.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally across the network would likely be constrained.
Control: Multicloud Visibility & Control
Mitigation: Establishing and maintaining command and control channels would likely be more challenging for the attacker.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained.
The scope of the ransomware's impact would likely be limited to the initially compromised workload.
Impact at a Glance
Affected Business Functions
- Network Operations
- Web Browsing
- SD-WAN Management
Estimated downtime: 3 days
Estimated loss: $50,000
Potential unauthorized network access and control, risk of arbitrary code execution, and privilege escalation.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to limit lateral movement within the network.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation of known vulnerabilities.
- • Utilize Cloud Firewall (ACF) to control and monitor outbound traffic, preventing unauthorized data exfiltration.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Regularly update and patch systems to mitigate known vulnerabilities and reduce the attack surface.



