CISA Adds One Known Exploited Vulnerability to Catalog
2026-03-26T15:24:22Z•d7f6aa68695f8fb0c8c9d725ea98a80970911ecdb67833609e3b29b4888b6e4f
CISACisco FMCCraft CMSIntuneKEVKnown Exploited VulnerabilitiesLangflowLaravel LivewireMFAMicrosoft SharePointRBACStrykerSynacor ZimbraWing FTPbuffer-overflowcode-injectioncross-site-scriptingdeserializationendpoint-managementhardeninginformation-disclosureleast-privilegepatchingremediationvulnerability-management
What happened
CISA published multiple KEV Catalog updates (Mar 18–25, 2026) adding several vulnerabilities with evidence of active exploitation and urging immediate remediation. Newly listed CVEs include code injection, deserialization, buffer overflow, cross-site scripting, and information-disclosure flaws across products such as Langflow, Craft CMS, Laravel Livewire, Apple products, Cisco Secure Firewall Management Center / Security Cloud Control (FMC/SCC), Microsoft SharePoint, Synacor Zimbra Collaboration Suite (ZCS), Wing FTP Server, and others. CISA also issued an alert urging hardening of endpoint‑/U
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- d7f6aa68695f8fb0c8c9d725ea98a80970911ecdb67833609e3b29b4888b6e4f
- Enrichment time
- 2026-03-26T15:24:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.