CISA Adds One Known Exploited Vulnerability to Catalog
2026-04-02T19:24:17Z•2885e4274403fd08afb3609f8af68abc24952c0accae733b2ac20da45d7e0e4a
AppleAqua Security TrivyBOD 22-01CISACitrix NetScalerCraft CMSF5 BIG-IPGoogle DawnKEV CatalogLangflowLaravel LivewireTrueConfactive exploitationcode injectionknown exploited vulnerabilityremediationremote code executionsupply chain integrityuse-after-freevulnerability management
What happened
CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. Affected products/vendors include TrueConf (CVE-2026-3502: download of code without integrity check), Google Dawn (CVE-2026-5281: use-after-free), Citrix NetScaler (CVE-2026-3055: out-of-bounds read), F5 BIG-IP (CVE-2025-53521: remote code execution), Aqua Security Trivy (CVE-2026-33634: embedded malicious code), Langflow (CVE-2026-33017: code injection), and multiple other products (CVE-2025-31277, CVE-2025-32432, CVE-2025-43510, CVE-2025-43520, CVE-2025-54068). C
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 2885e4274403fd08afb3609f8af68abc24952c0accae733b2ac20da45d7e0e4a
- Enrichment time
- 2026-04-02T19:24:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.