CISA Adds Aquasecurity Trivy Scanner Vulnerability to KEV Catalog
ID: 9010a410-2edf-5baa-8d02-84ee56a22940
STIX ID: report--9010a410-2edf-5baa-8d02-84ee56a22940
Feed Name: cybersecurityNews.com
CISA has added CVE-2026-33634 to its Known Exploited Vulnerabilities catalog: an embedded malicious-code flaw in the Trivy scanner that can convert the scanner into a backdoor for CI/CD environments. The vulnerability can expose authentication tokens, SSH keys, cloud credentials, and other sensitive configuration data, enabling attackers to fully compromise pipelines and perform supply-chain attacks; CISA reports active exploitation and requires urgent remediation (patching or discontinuation) and secret rotation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
