logo

CISA Adds Critical Aquasecurity Trivy Scanner Vulnerability to KEV Catalog

ID: 6ca7a8e9-7777-5710-b73e-7da7433f9890

STIX ID: report--6ca7a8e9-7777-5710-b73e-7da7433f9890

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-27

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive Summary:** CISA added CVE-2026-33634 — a malicious-code vulnerability (CWE-506) in the Trivy scanner used in CI/CD pipelines — to its Known Exploited Vulnerabilities catalog; successful exploitation can give attackers full visibility into CI/CD environments and allow theft of development tokens, SSH keys, cloud credentials, and database passwords, prompting an FCEB remediation deadline and guidance to cease Trivy use until mitigated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.