CISA Adds One Known Exploited Vulnerability to Catalog

2026-04-01T19:24:13Z5218ac3ee53c5f1e7732401d291485877330d3bda2641d59b45ee3ff6b02f957
AppleAqua TrivyBOD 22-01Cisco Secure FMCCitrix NetScalerCraft CMSF5 BIG-IPGoogle DawnKEV CatalogLangflowLaravel Livewireactive exploitationcode injectiondeserializationout-of-bounds readremote code executionsupply-chainuse-after-freevulnerability management

What happened

Between Mar 20 and Apr 1, 2026, CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog (per BOD 22-01) based on evidence of active exploitation. Affected products include Google Dawn, Citrix NetScaler, F5 BIG‑IP, Aqua Security Trivy, Langflow, Cisco Secure FMC/SCC, Apple multiple products, Craft CMS, and Laravel Livewire. CISA urges timely remediation under BOD 22‑01; these vulnerabilities include remote code execution, code injection, use‑after‑free, out‑of‑bounds read, and deserialization issues and represent a significant risk to enterprise networks.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
5218ac3ee53c5f1e7732401d291485877330d3bda2641d59b45ee3ff6b02f957
Enrichment time
2026-04-01T19:24:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.