logo

CISA Adds Qualcomm and VMware Flaws to Known Exploited Catalog

ID: f15fe209-4c26-5946-bd7d-51202d0cb019

STIX ID: report--f15fe209-4c26-5946-bd7d-51202d0cb019

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-04

Date Updated: 2026-04-23

Author: Ddos

...
...

CISA added two high-priority vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-21385, a Qualcomm graphics integer overflow that can trigger memory corruption and has been observed in limited targeted exploitation, and CVE-2026-22719, a Broadcom-tracked command injection in VMware Aria Operations (CVSS 8.1) enabling unauthenticated RCE with reports of possible in-the-wild exploitation; federal agencies are required to remediate the VMware issue by March 24, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.