U.S. CISA adds Google Chrome flaws to its Known Exploited Vulnerabilities catalog
2026-03-14T02:51:47Z•fe56e20ee188f1a842c8c20b1ef08f6a9794dfa611cbfc78e507a754d08ec8a7
AVreconAlly WordPress pluginApple iOS CorunaCISAChrome vulnerabilitiesENISAGoogle ChromeHive0163Known Exploited VulnerabilitiesPoland National Centre for Nuclear ResearchSQL injectionSlopolySocksEscortbotnet takedownincident detectionn8nransomwaresecure package managerssupply chain
What happened
Recent security reporting highlights multiple high-impact incidents and advisories: U.S. CISA added several actively exploited flaws to its Known Exploited Vulnerabilities (KEV) list, including an n8n vulnerability (CVE-2025-68613, CVSS 10.0). Google released fixes for two Chrome vulnerabilities (CVE-2026-3909, CVE-2026-3910) that are being exploited in the wild. A critical unauthenticated SQL injection (CVE-2026-2413) was disclosed in the Ally WordPress plugin (used on ~400k sites). Law enforcement disrupted the SocksEscort proxy service and the AVrecon botnet (≈360k infected devices). IBM X-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- fe56e20ee188f1a842c8c20b1ef08f6a9794dfa611cbfc78e507a754d08ec8a7
- Enrichment time
- 2026-03-14T02:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.