CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2025-54068

Laravel Livewire Code Injection Vulnerability

Vendor: Laravel

Product: Livewire

Added: 2026-03-20

Due Date: 2026-04-03

Description:

Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-94

CVE-2025-43510

Apple Multiple Products Improper Locking Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2026-03-20

Due Date: 2026-04-03

Description:

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-667

CVE-2025-43520

Apple Multiple Products Classic Buffer Overflow Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2026-03-20

Due Date: 2026-04-03

Description:

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-120

CVE-2025-31277

Apple Multiple Products Buffer Overflow Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2026-03-20

Due Date: 2026-04-03

Description:

Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-119

CVE-2026-20131

Ransomware

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

Vendor: Cisco

Product: Secure Firewall Management Center (FMC)

Added: 2026-03-19

Due Date: 2026-03-22

Description:

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2025-66376

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability

Vendor: Synacor

Product: Zimbra Collaboration Suite (ZCS)

Added: 2026-03-18

Due Date: 2026-04-01

Description:

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-79

CVE-2026-20963

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Vendor: Microsoft

Product: SharePoint

Added: 2026-03-18

Due Date: 2026-03-21

Description:

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2025-47813

Wing FTP Server Information Disclosure Vulnerability

Vendor: Wing FTP Server

Product: Wing FTP Server

Added: 2026-03-16

Due Date: 2026-03-30

Description:

Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-209

CVE-2026-3910

Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2026-03-13

Due Date: 2026-03-27

Description:

Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-119

CVE-2026-3909

Google Skia Out-of-Bounds Write Vulnerability

Vendor: Google

Product: Skia

Added: 2026-03-13

Due Date: 2026-03-27

Description:

Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-787

CVE-2025-68613

n8n Improper Control of Dynamically-Managed Code Resources Vulnerability

Vendor: n8n

Product: n8n

Added: 2026-03-11

Due Date: 2026-03-25

Description:

n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-913

CVE-2021-22054

Omnissa Workspace ONE Server-Side Request Forgery

Vendor: Omnissa

Product: Workspace One UEM

Added: 2026-03-09

Due Date: 2026-03-23

Description:

Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-918

CVE-2025-26399

Ransomware

SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

Vendor: SolarWinds

Product: Web Help Desk

Added: 2026-03-09

Due Date: 2026-03-12

Description:

SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2026-1603

Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability

Vendor: Ivanti

Product: Endpoint Manager (EPM)

Added: 2026-03-09

Due Date: 2026-03-23

Description:

Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-288

CVE-2017-7921

Hikvision Multiple Products Improper Authentication Vulnerability

Vendor: Hikvision

Product: Multiple Products

Added: 2026-03-05

Due Date: 2026-03-26

Description:

Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-287