CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2026-33634

Aquasecurity Trivy Embedded Malicious Code Vulnerability

Vendor: Aquasecurity

Product: Trivy

Added: 2026-03-26

Due Date: 2026-04-09

Description:

Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-506

CVE-2026-33017

Langflow Code Injection Vulnerability

Vendor: Langflow

Product: Langflow

Added: 2026-03-25

Due Date: 2026-04-08

Description:

Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-94 CWE-95 CWE-306

CVE-2025-32432

Craft CMS Code Injection Vulnerability

Vendor: Craft CMS

Product: Craft CMS

Added: 2026-03-20

Due Date: 2026-04-03

Description:

Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-94

CVE-2025-54068

Laravel Livewire Code Injection Vulnerability

Vendor: Laravel

Product: Livewire

Added: 2026-03-20

Due Date: 2026-04-03

Description:

Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-94

CVE-2025-43510

Apple Multiple Products Improper Locking Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2026-03-20

Due Date: 2026-04-03

Description:

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-667

CVE-2025-43520

Apple Multiple Products Classic Buffer Overflow Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2026-03-20

Due Date: 2026-04-03

Description:

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-120

CVE-2025-31277

Apple Multiple Products Buffer Overflow Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2026-03-20

Due Date: 2026-04-03

Description:

Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-119

CVE-2026-20131

Ransomware

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

Vendor: Cisco

Product: Secure Firewall Management Center (FMC)

Added: 2026-03-19

Due Date: 2026-03-22

Description:

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2025-66376

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability

Vendor: Synacor

Product: Zimbra Collaboration Suite (ZCS)

Added: 2026-03-18

Due Date: 2026-04-01

Description:

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-79

CVE-2026-20963

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Vendor: Microsoft

Product: SharePoint

Added: 2026-03-18

Due Date: 2026-03-21

Description:

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2025-47813

Wing FTP Server Information Disclosure Vulnerability

Vendor: Wing FTP Server

Product: Wing FTP Server

Added: 2026-03-16

Due Date: 2026-03-30

Description:

Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-209

CVE-2026-3910

Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2026-03-13

Due Date: 2026-03-27

Description:

Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-119

CVE-2026-3909

Google Skia Out-of-Bounds Write Vulnerability

Vendor: Google

Product: Skia

Added: 2026-03-13

Due Date: 2026-03-27

Description:

Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-787

CVE-2025-68613

n8n Improper Control of Dynamically-Managed Code Resources Vulnerability

Vendor: n8n

Product: n8n

Added: 2026-03-11

Due Date: 2026-03-25

Description:

n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-913

CVE-2021-22054

Omnissa Workspace ONE Server-Side Request Forgery

Vendor: Omnissa

Product: Workspace One UEM

Added: 2026-03-09

Due Date: 2026-03-23

Description:

Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-918