CISA Triggers Federal Patch Clock on Cisco, Chrome and Arista Bugs Under KEV

Three vulnerabilities added to the Known Exploited Vulnerabilities catalog activate BOD 22-01 remediation deadlines for civilian agencies.

ThreatVectr Newsdesk· 2 min read
CISA Triggers Federal Patch Clock on Cisco, Chrome and Arista Bugs Under KEV
Share

The Cybersecurity and Infrastructure Security Agency on Tuesday added three flaws to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation.

The additions trigger the remediation timeline set out in Binding Operational Directive 22-01, which requires Federal Civilian Executive Branch agencies to patch listed vulnerabilities by the date CISA assigns at the time of cataloging. Private-sector operators are not bound by BOD 22-01, but the directive's preamble — and CISA's repeated public guidance — recommends KEV-listed flaws be treated as urgent across all sectors.

The headline entry is CVE-2026-20245, a CVSS 7.8 improper-output-encoding flaw in Cisco Catalyst SD-WAN Manager. Cisco's advisory characterizes the issue as exploitable through crafted input handled by the management interface, with downstream consequences for authenticated session integrity. Operators running affected Catalyst SD-WAN Manager builds should consult the Cisco Security Advisories portal for fixed-release mapping.

The second and third entries cover a Chromium-family browser flaw and an Arista networking defect, both flagged by CISA as carrying confirmed in-the-wild exploitation. Google's Chrome release channel notes and Arista's product security advisory pages remain the authoritative references for patched versions.

A few procedural points worth flagging.

KEV additions are not rulemakings. There is no proposed-versus-final distinction here, no comment period, and no Federal Register publication. CISA adds an entry once it determines the statutory criteria in BOD 22-01 — a CVE ID, reliable evidence of active exploitation, and clear remediation guidance — are met. Agencies have, by default, three weeks to remediate, though CISA may compress that window for higher-severity items.

Enforcement runs through CISA's coordination with the Office of Management and Budget. Agencies that miss KEV deadlines face escalation rather than monetary penalty. For regulated private entities, KEV status increasingly bleeds into other obligations: the SEC's Item 1.05 Form 8-K materiality analysis, CIRCIA's forthcoming covered-incident reporting once final rules take effect, and state-level breach notification regimes that weigh known-exploited status when assessing reasonableness of controls.

CISA reiterated its standing recommendation that all organizations — not only FCEB agencies — prioritize KEV-listed vulnerabilities within their vulnerability management workflows. The agency does not publish exploitation attribution alongside KEV entries, so defenders should pair the listing with vendor advisories and any threat-intelligence reporting available through ISACs.

The catalog now exceeds 1,300 entries since its December 2021 launch. Patch deadlines for the three new items are listed in the catalog's per-entry metadata.

© 2026 Threat Vectr