CISA Adds One Known Exploited Vulnerability to Catalog

2026-04-02T19:24:17Z2885e4274403fd08afb3609f8af68abc24952c0accae733b2ac20da45d7e0e4a
AppleAqua Security TrivyBOD 22-01CISACitrix NetScalerCraft CMSF5 BIG-IPGoogle DawnKEV CatalogLangflowLaravel LivewireTrueConfactive exploitationcode injectionknown exploited vulnerabilityremediationremote code executionsupply chain integrityuse-after-freevulnerability management

What happened

CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. Affected products/vendors include TrueConf (CVE-2026-3502: download of code without integrity check), Google Dawn (CVE-2026-5281: use-after-free), Citrix NetScaler (CVE-2026-3055: out-of-bounds read), F5 BIG-IP (CVE-2025-53521: remote code execution), Aqua Security Trivy (CVE-2026-33634: embedded malicious code), Langflow (CVE-2026-33017: code injection), and multiple other products (CVE-2025-31277, CVE-2025-32432, CVE-2025-43510, CVE-2025-43520, CVE-2025-54068). C

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
2885e4274403fd08afb3609f8af68abc24952c0accae733b2ac20da45d7e0e4a
Enrichment time
2026-04-02T19:24:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.