Why These Critical Vulnerability Patches Demand Immediate Action
Critical vulnerability patches for Fortinet, Ivanti, SAP, Cisco, Chrome, and Arista address remote code execution flaws and access control weaknesses that expose systems to rapid compromise across network, application, and infrastructure layers, making a structured and risk-based security patch priority essential for IT and security teams that manage enterprise environments. Fortinet, Ivanti, and SAP have released updates for multiple high‑impact bugs, with CVSS scores up to 10.0 and impacts including remote code execution, admin account takeover, and sensitive data exposure. At the same time, CISA has added Cisco SD‑WAN Manager, Chrome V8, and Arista EOS issues to its Known Exploited Vulnerabilities catalog, confirming active exploitation threats. While not every new flaw is known to be exploited yet, the combination of critical CVSS scores and confirmed attacks in related products means delay creates a clear path for attackers to pivot through browsers, network appliances, and ERP systems.
Fortinet and Ivanti: Internet-Facing Remote Code Execution Flaws
Fortinet’s CVE-2026-25089 is a command injection vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI with a CVSS score of 9.1. An unauthenticated attacker can send crafted HTTP requests to execute operating system commands on affected versions, turning a security appliance into an entry point. Ivanti Sentry faces even more severe issues: CVE-2026-10520 is a CVSS 10.0 operating system command injection bug that allows remote unauthenticated users to gain root-level remote code execution, while CVE-2026-10523 (CVSS 9.9) enables authentication bypass and creation of arbitrary administrative accounts. Security teams should prioritize Ivanti Sentry systems exposed to the internet, then FortiSandbox deployments. Patch or upgrade to the fixed versions immediately, restrict direct internet access until updates are applied, and review authentication logs for suspicious admin account creation or unexpected command activity on these devices.
SAP NetWeaver and Commerce: Protecting ERP and Business Data
SAP has issued critical vulnerability patches across NetWeaver AS ABAP, ABAP Platform, Commerce Cloud, Data Hub, and NetWeaver AS Java. CVE-2026-44748 (CVSS 9.9) is an XML signature wrapping flaw in SAML authentication for NetWeaver AS ABAP and ABAP Platform that can let attackers tamper with identity data. According to SAP security company Onapsis, “Due to an improper XML signature verification, the manipulated identity information is accepted, leading to unauthorized access to sensitive user data and potential disruption of normal system usage.” Other CVSS 9.0+ issues include memory corruption (CVE-2026-27671), Spring security weaknesses (CVE-2026-22732), and directory traversal in NetWeaver AS Java (CVE-2026-40128). Patch all affected SAP components quickly, starting with SAML-enabled systems and externally reachable application servers. Coordinate with SAP BASIS and application owners to schedule downtime, then re-test SSO flows and access controls after patching.
CISA KEV Additions: Cisco SD-WAN, Chrome V8, and Arista EOS
CISA’s addition of three flaws to the Known Exploited Vulnerabilities catalog signals active exploitation threats that must influence security patch priority. CVE-2026-20245 (CVSS 7.8) affects Cisco Catalyst SD‑WAN Manager; a local authenticated attacker can gain root command execution by supplying a crafted file. CVE-2026-11645 (CVSS 8.8) is an out‑of‑bounds read/write bug in Chrome’s V8 engine, allowing remote code execution inside the browser sandbox via crafted HTML. CVE-2026-7473 (CVSS 6.9) in Arista EOS causes switches to decapsulate and forward unexpected tunnel traffic when configured as a tunnel endpoint. Arista has confirmed the issue is “reported as being exploited in the wild” and has chosen not to provide a patch, instead documenting mitigations based on upstream or local ACLs. IT teams must treat these KEV‑listed vulnerabilities as immediate risks, aligning remediation with CISA’s required mitigation timelines where applicable.
A Practical Patch and Mitigation Plan for Security Teams
Security teams should structure their response around two axes: CVSS severity and evidence of active exploitation. First, fast‑track Ivanti Sentry (CVE-2026-10520, CVSS 10.0) and related CVSS 9.9–9.1 issues in Ivanti, SAP, and Fortinet, focusing on systems exposed to the internet or handling sensitive data. Next, handle KEV‑listed vulnerabilities in Cisco SD‑WAN Manager, Chrome V8, and Arista EOS, prioritizing user browsers and network edge devices. Where no patch exists, as with Arista CVE-2026-7473, follow the vendor’s guidance to apply ACLs either upstream or on affected switches to allow only legitimate tunnel traffic or block malicious packets. Throughout, maintain strong browser update policies, enforce least privilege on administrative interfaces, and monitor logs for anomalies that match known exploit paths, such as unexpected tunnel decapsulation, unusual RFC requests, or repeated SAML authentication anomalies.






