U.S. CISA adds a flaw in Google Dawn to its Known Exploited Vulnerabilities catalog
2026-04-02T02:51:48Z•cf1a778a87922fd670b2cc9c7bf99b604c71f40d9262db464e2175111848e8f2
AnthropicAxiosCISACVE-2026-3055CVE-2026-5281ChromeCitrix NetScalerClaude CodeDutch Ministry of FinanceGoogle DawnKnown Exploited VulnerabilitiesLiteLLMLloyds Banking GroupSentinelOneUNC1069WebGPUdata breachnpmsupply chainuse-after-freezero-day
What happened
Multiple high-impact security events: CISA added a Google Chrome/WebGPU Dawn use-after-free (CVE-2026-5281, CVSS 8.8) — an actively exploited zero-day — to its Known Exploited Vulnerabilities catalog and Google released a Chrome update. CISA also added a critical Citrix NetScaler flaw (CVE-2026-3055, CVSS 9.3) to KEV. Several supply‑chain and data incidents were reported: the Axios npm account was hijacked to distribute RATs (Google links the compromise to North Korea‑linked UNC1069), Anthropic accidentally leaked Claude Code via npm, SentinelOne autonomously blocked a trojaned LiteLLM package
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- cf1a778a87922fd670b2cc9c7bf99b604c71f40d9262db464e2175111848e8f2
- Enrichment time
- 2026-04-02T02:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.