U.S. CISA adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog

2026-03-22T14:51:46Ze0eb17ed5c28004d16265d9d61fdb8a9844a8ef4a83d41259ac90b874a8e08f3
AISURUAdobe CommerceAppleCISACorunaCraft CMSDarkSwordIoT botnetJackSkidKEVKimwolfLaravel LivewireMagentoNaviaPolyShellWorldLeaksXSSbotnet takedown (DoJ)‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎data breachdefacementiOSknown exploited vulnerabilitiesransomwareunauthenticated file uploadweb application

What happened

SecurityAffairs feed: U.S. CISA added multiple vulnerabilities (affecting Apple, Laravel Livewire and Craft CMS) to its Known Exploited Vulnerabilities (KEV) catalog. Sansec disclosed a critical 'PolyShell' flaw in the Magento/Adobe Commerce REST API allowing unauthenticated file uploads (and possible XSS) in older versions. A large-scale campaign has defaced over 7,500 Magento sites. WorldLeaks ransomware breached Los Angeles systems (including Metro) causing service disruption. Navia Benefit Solutions disclosed a data breach impacting ~2.7M people. Apple warned outdated iPhones are at risk (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
e0eb17ed5c28004d16265d9d61fdb8a9844a8ef4a83d41259ac90b874a8e08f3
Enrichment time
2026-03-22T14:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · U.S. CISA adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog · Baitaphish