logo

CISA Adds Aquasecurity Trivy Scanner Vulnerability to KEV Catalog

ID: 9010a410-2edf-5baa-8d02-84ee56a22940

STIX ID: report--9010a410-2edf-5baa-8d02-84ee56a22940

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-28

Date Updated: 2026-04-21

Author: Abinaya

...
...

CISA has added CVE-2026-33634 to its Known Exploited Vulnerabilities catalog: an embedded malicious-code flaw in the Trivy scanner that can convert the scanner into a backdoor for CI/CD environments. The vulnerability can expose authentication tokens, SSH keys, cloud credentials, and other sensitive configuration data, enabling attackers to fully compromise pipelines and perform supply-chain attacks; CISA reports active exploitation and requires urgent remediation (patching or discontinuation) and secret rotation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.