U.S. CISA adds a flaw in Google Dawn to its Known Exploited Vulnerabilities catalog

2026-04-02T02:51:48Zcf1a778a87922fd670b2cc9c7bf99b604c71f40d9262db464e2175111848e8f2
AnthropicAxiosCISACVE-2026-3055CVE-2026-5281ChromeCitrix NetScalerClaude CodeDutch Ministry of FinanceGoogle DawnKnown Exploited VulnerabilitiesLiteLLMLloyds Banking GroupSentinelOneUNC1069WebGPUdata breachnpmsupply chainuse-after-freezero-day

What happened

Multiple high-impact security events: CISA added a Google Chrome/WebGPU Dawn use-after-free (CVE-2026-5281, CVSS 8.8) — an actively exploited zero-day — to its Known Exploited Vulnerabilities catalog and Google released a Chrome update. CISA also added a critical Citrix NetScaler flaw (CVE-2026-3055, CVSS 9.3) to KEV. Several supply‑chain and data incidents were reported: the Axios npm account was hijacked to distribute RATs (Google links the compromise to North Korea‑linked UNC1069), Anthropic accidentally leaked Claude Code via npm, SentinelOne autonomously blocked a trojaned LiteLLM package

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
cf1a778a87922fd670b2cc9c7bf99b604c71f40d9262db464e2175111848e8f2
Enrichment time
2026-04-02T02:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.