U.S. CISA adds Google Chrome flaws to its Known Exploited Vulnerabilities catalog

2026-03-14T02:51:47Zfe56e20ee188f1a842c8c20b1ef08f6a9794dfa611cbfc78e507a754d08ec8a7
AVreconAlly WordPress pluginApple iOS CorunaCISAChrome vulnerabilitiesENISAGoogle ChromeHive0163Known Exploited VulnerabilitiesPoland National Centre for Nuclear ResearchSQL injectionSlopolySocksEscortbotnet takedownincident detectionn8nransomwaresecure package managerssupply chain

What happened

Recent security reporting highlights multiple high-impact incidents and advisories: U.S. CISA added several actively exploited flaws to its Known Exploited Vulnerabilities (KEV) list, including an n8n vulnerability (CVE-2025-68613, CVSS 10.0). Google released fixes for two Chrome vulnerabilities (CVE-2026-3909, CVE-2026-3910) that are being exploited in the wild. A critical unauthenticated SQL injection (CVE-2026-2413) was disclosed in the Ally WordPress plugin (used on ~400k sites). Law enforcement disrupted the SocksEscort proxy service and the AVrecon botnet (≈360k infected devices). IBM X-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
fe56e20ee188f1a842c8c20b1ef08f6a9794dfa611cbfc78e507a754d08ec8a7
Enrichment time
2026-03-14T02:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · U.S. CISA adds Google Chrome flaws to its Known Exploited Vulnerabilities catalog · Baitaphish