logo

U.S. CISA adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog

ID: edfb873e-f469-51de-a74e-e4112658bad1

STIX ID: report--edfb873e-f469-51de-a74e-e4112658bad1

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-03-22

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA added several high-severity vulnerabilities—affecting Apple products, Craft CMS, and Laravel Livewire—to its Known Exploited Vulnerabilities catalog after reports of active exploitation: an iOS exploit kit called DarkSword targeting Apple flaws, Craft CMS RCE and chained framework issues used to breach servers and deploy a PHP webshell, and CVE-2025-54068 linked to MuddyWater operations; agencies are ordered to remediate by April 3, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.