Post Date: 2026/06/17

【Vulnerability Alert】CISA Adds 7 Known Exploited Vulnerabilities to KEV Catalog (2026/06/08-2026/06/14)


  1. 【CVE-2026-11645】Google Chromium V8 Out-of-Bounds Read and Write Vulnerability (CVSS v3.1: 8.8)
    • 【Exploited by Ransomware: Unknown】 An out-of-bounds read and write vulnerability exists in Google Chromium V8. A remote attacker could execute arbitrary code within the sandbox via a specially crafted HTML page. This vulnerability may affect various web browsers using the Chromium core, including but not limited to Google Chrome, Microsoft Edge, and Opera.
    • 【Affected Platforms】Please refer to the affected versions listed by the official advisory
  2. 【CVE-2026-7473】Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability (CVSS v3.1: 5.8)
    • 【Exploited by Ransomware: Unknown】 An Incomplete Comparison with Missing Factors vulnerability exists in Arista Extensible Operating System. When a switch receives an unexpected tunneled packet whose destination IP address matches its configured decapsulation IP, it may incorrectly perform decapsulation and forward it, leading to unexpected traffic handling behavior.
    • 【Affected Platforms】Please refer to the affected versions listed by the official advisory
  1. 【CVE-2026-20245】Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability (CVSS v3.1: 7.8)
  2. CVE-2026-10520】Ivanti Sentry OS Command Injection Vulnerability (CVSS v3.1: 10.0)
    • 【Exploited by Ransomware: Unknown】 An operating system command injection vulnerability exists in Ivanti Sentry, which could allow an unauthenticated remote user to execute remote code with root privileges. An attacker can successfully exploit this vulnerability when the Sentry appliance is in an unmanaged state and its endpoints are accessible from the external network. If mTLS is used with EPMM, or HTTPS access is restricted through Neurons for MDM, external attackers will be prevented from accessing the relevant interfaces.
    • 【Affected Platforms】Please refer to the affected versions listed by the official advisory
  1. 【CVE-2026-35273】Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability (CVSS v3.1: 9.8)
    • 【Exploited by Ransomware: Known】 A missing authentication for critical function vulnerability exists in Oracle PeopleSoft Enterprise PeopleTools. An unauthenticated attacker could exploit this vulnerability to gain control of PeopleSoft Enterprise PeopleTools.
    • 【Affected Platforms】Please refer to the affected versions listed by the official advisory https://www.oracle.com/security-alerts/alert-cve-2026-35273.html
  1. 【CVE-2026-20245】 The vendor has released a security patch for this vulnerability, please update to the relevant version.
  1. 【CVE-2026-10520】 The vendor has released a security patch for this vulnerability, please update to the relevant version.
  1. 【CVE-2026-35273】 The vendor has released a security patch for this vulnerability, please update to the relevant version.

Computer and Communication Center
Network Systems Division