CISA KEV
CVE-2026-20133: Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Unauthenticated SD-WAN Manager API requests can expose sensitive operating-system information. This CVE does not inherit neighboring flaws' root or overwrite impacts, nor their release exclusions; preserve API evidence and use the disclosure-specific fix guidance.
CVE-2026-7473: Arista EOS tunnel decapsulation validation flaw
Affected Arista EOS switches can forward unexpected tunnel traffic sent to a configured decapsulation IP. Arista specifies ACL mitigation, not a software upgrade; plan filters around shared-IP services and potentially disruptive TCAM changes.
CVE-2026-20245: Cisco Catalyst SD-WAN authenticated root privilege escalation
An attacker with netadmin privileges can use a crafted file to gain root on affected SD-WAN control components. Preserve admin-tech before upgrading, then inspect indicators and verify downstream edge-device configuration.
CVE-2026-50751: Check Point deprecated IKEv1 VPN authentication bypass
Check Point's exploited VPN bypass requires Remote Access or Mobile Access, IKEv1, accepted legacy clients and no mandatory machine certificate. Gateway and Spark remediation differ; review suspicious VPN sessions separately from installing the appropriate fix.
CVE-2025-48595: Android Framework privilege escalation
Android Framework integer overflow can enable local privilege escalation beyond normal device permissions. Install the OEM security update and verify its reported patch level; this platform issue is not limited to Pixel devices.
CVE-2026-0257: PAN-OS GlobalProtect authentication bypass
GlobalProtect authentication-override cookies can permit unauthorized VPN connections under the affected certificate configuration. Coordinate fixes across every cookie-generating and accepting portal or gateway, including hybrid Prisma Access deployments, and investigate sessions separately from patching.
CVE-2026-45498: Microsoft Defender local denial of service
The exploited Microsoft Defender flaw can interrupt protection through denial of service. Verify the Antimalware Platform update on each endpoint and examine Defender health telemetry; a currently healthy service does not rule out earlier disruption.
CVE-2026-41091: Microsoft Malware Protection Engine privilege escalation
A link-following flaw in Microsoft Malware Protection Engine can let an authorized local attacker gain SYSTEM privileges. Verify the installed engine update and review endpoint telemetry; this is not unauthenticated remote takeover.
CVE-2010-0806: Legacy Internet Explorer use-after-free RCE
Crafted content viewed in affected legacy Internet Explorer versions can run code with the user's rights. MS10-018 documents the historical fix; it does not restore support, so surviving unsupported browser and platform combinations require retirement.
CVE-2010-0249: Legacy Internet Explorer use-after-free RCE
CVE-2010-0249 can execute code through crafted web content in legacy Internet Explorer. Microsoft's original bulletin reported limited attacks; the 2026 KEV addition is separate history, not a new disclosure or justification for retaining unsupported systems.
