The U.S. Cybersecurity and Infrastructure Security Agency has officially updated its Known Exploited Vulnerabilities catalog to include three recent flaws identified in products from Cisco, Google, and Arista. This move follows confirmed reports that these security gaps are being actively leveraged in the wild. Federal agencies and private organizations are encouraged to prioritize these patches to mitigate the risk of unauthorized access or system compromise.
Among the newly listed entries is CVE-2026-20245, which affects the Cisco Catalyst SD-WAN Manager. This specific vulnerability has been assigned a CVSS score of 7.8, indicating a high severity level. The issue stems from an improper encoding or escaping of output flaw, which could potentially allow an attacker to execute malicious actions within the management interface. Alongside the Cisco flaw, the update also addresses critical vulnerabilities identified in the Chrome web browser and Arista network equipment.
CISA maintains the KEV catalog as a resource to help organizations distinguish between theoretical risks and threats that are currently experiencing documented exploitation. By including these specific flaws from Cisco, Google, and Arista, the agency signaling that the window for remediation is closing as threat actors are already utilizing these vectors for cyberattacks.
For IT directors and operations leaders, these additions serve as a direct prompt for immediate patching of affected enterprise infrastructure. Managing these specific vulnerabilities is a critical step for MSPs and internal IT teams responsible for securing software-defined networking environments and browser-based interfaces against active exploitation trends.
The BroadVision view
The inclusion of these vulnerabilities in the CISA catalog indicates that these flaws are being actively leveraged by threat actors. For mid-market IT teams, this necessitates immediate patching or the application of vendor-recommended mitigations to protect network infrastructure. Regular assessment of asset vulnerability remains a standard requirement for maintaining a secure environment. Learn more about our strategic IT services.
