CISA Adds One Known Exploited Vulnerability to Catalog

2026-03-26T15:24:22Zd7f6aa68695f8fb0c8c9d725ea98a80970911ecdb67833609e3b29b4888b6e4f
CISACisco FMCCraft CMSIntuneKEVKnown Exploited VulnerabilitiesLangflowLaravel LivewireMFAMicrosoft SharePointRBACStrykerSynacor ZimbraWing FTPbuffer-overflowcode-injectioncross-site-scriptingdeserializationendpoint-managementhardeninginformation-disclosureleast-privilegepatchingremediationvulnerability-management

What happened

CISA published multiple KEV Catalog updates (Mar 18–25, 2026) adding several vulnerabilities with evidence of active exploitation and urging immediate remediation. Newly listed CVEs include code injection, deserialization, buffer overflow, cross-site scripting, and information-disclosure flaws across products such as Langflow, Craft CMS, Laravel Livewire, Apple products, Cisco Secure Firewall Management Center / Security Cloud Control (FMC/SCC), Microsoft SharePoint, Synacor Zimbra Collaboration Suite (ZCS), Wing FTP Server, and others. CISA also issued an alert urging hardening of endpoint‑/U

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
d7f6aa68695f8fb0c8c9d725ea98a80970911ecdb67833609e3b29b4888b6e4f
Enrichment time
2026-03-26T15:24:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.