logo

Active Exploits: CISA Adds Critical Craft CMS and Apple ‘DarkSword’ Flaws to KEV

ID: 73a6fb83-b701-5866-95f1-a345a0140360

STIX ID: report--73a6fb83-b701-5866-95f1-a345a0140360

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-03-21

Date Updated: 2026-04-23

Author: Ddos

...
...

CISA added five high-impact, actively weaponized vulnerabilities to its KEV catalog — notably a CVSS 10.0 Craft CMS RCE and a CVSS 9.2 Laravel Livewire unauthenticated RCE — alongside multiple iOS/macOS/Safari flaws exploited via malicious web content and linked to the DarkSword exploit chain. Google GTIG attribution notes DarkSword delivers a suite of Ghost payloads (GHOSTBLADE, GHOSTKNIFE, GHOSTSABER) that steal sensitive data and provide persistent backdoors; CISA mandates remediation by April 3, 2026 and recommends immediate patching and IoC hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.