CISA Adds Five Known Exploited Vulnerabilities to Catalog

2026-03-20T17:24:20Z5b1bb3c95b22b8779e5bdd5d288dfe2b3632eb55a2a467e0d59cb65b0f53db9c
AppleBOD-22-01CISAChromium-V8CiscoCraftCMSGoogle-SkiaIntune-hardeningKEVKnown-Exploited-VulnerabilitiesLaravel-LivewireMicrosoft-SharePointSynacor-ZimbraWing-FTPactive-exploitationbuffer-overflowcode-injectioncross-site-scriptingdeserializationendpoint-managementinformation-disclosurepatchingvulnerability-management

What happened

CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. Newly listed CVEs include CVE-2025-31277, CVE-2025-32432, CVE-2025-43510, CVE-2025-43520, CVE-2025-54068, CVE-2026-20131, CVE-2026-20963, CVE-2025-66376, CVE-2025-47813, CVE-2026-3909, and CVE-2026-3910 affecting Apple products, Craft CMS, Laravel Livewire, Cisco Secure FMC/SCC, Microsoft SharePoint, Synacor Zimbra, Wing FTP Server, and Google Skia/Chromium V8. Reported weakness types include buffer overflows, code injection, deserialization of untrusted data, XSS,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
5b1bb3c95b22b8779e5bdd5d288dfe2b3632eb55a2a467e0d59cb65b0f53db9c
Enrichment time
2026-03-20T17:24:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.