Skip to main content
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogwidely-deployed-product-advisoryendpoint-software-vulnerability

CISA Adds Five Actively Exploited Vulnerabilities to the KEV Catalog

Updated 2mo agoFirst seen Mar 5, 202613 sources

CISA added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation, urging organizations to prioritize remediation and reminding U.S. Federal Civilian Executive Branch (FCEB) agencies that BOD 22-01 requires fixes by mandated due dates. The newly added KEVs are CVE-2017-7921 (Hikvision improper authentication), CVE-2021-22681 (Rockwell insufficiently protected credentials), and three Apple issues: CVE-2021-30952 (integer overflow/wraparound), CVE-2023-41974 (iOS/iPadOS use-after-free), and CVE-2023-43000 (use-after-free affecting multiple Apple products). CISA emphasized that KEV-listed flaws are common attack vectors and represent elevated risk, even for non-federal organizations.

CISA’s public kev-data repository reflects the same update, increasing the catalog count from 1531 to 1536 and recording a remediation due date of 2026-03-26 for at least CVE-2017-7921 (with required action to apply vendor mitigations or discontinue use if unavailable). Separately, Cisco Talos published a 2025 CVE retrospective that provides broader context on the growing volume of vulnerabilities and KEV additions, noting a year-over-year increase in KEVs and highlighting persistent exploitation of older CVEs; however, it does not add incident-specific details about the five newly listed KEVs beyond reinforcing the operational importance of patching and compensating controls for unpatchable systems.

Share:
CISA Adds Five Actively Exploited Vulnerabilities to the KEV Catalog
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Mar 26, 20262mo ago

Nuclei adds detection templates for five KEV flaws in Fortinet, SonicWall, and Qlik

A ProjectDiscovery pull request added Nuclei detection templates for five CISA KEV-listed vulnerabilities affecting Fortinet FortiOS, SonicWall SonicOS, SonicWall SMA 1000, and Qlik Sense Enterprise. The reference says the flaws are actively exploited, including by ransomware groups such as Akira, Fog, and Cactus, and that the templates are detection-only without exploit payloads.

Add 5 KEV CVE templates (Fortinet, SonicWall, Qlik Sense) by ElromEvedElElyon · Pull Request #15698 · projectdiscovery/nuclei-templates · GitHub
Mar 20, 20262mo ago

Researchers link March 20 Apple KEV flaws to DarkSword exploit kit

Researchers from Google Threat Intelligence Group, iVerify, and Lookout reported that the three Apple vulnerabilities added by CISA to KEV on March 20, 2026 were linked to the DarkSword iOS exploit kit used to deliver malware. The same reporting also tied the Craft CMS flaw to in-the-wild exploitation documented by Orange Cyberdefense and associated the Laravel Livewire flaw with attacks by the Iran-linked MuddyWater APT group.

U.S. CISA adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog

CISA sets April 3 deadline for federal remediation of March 20 KEV additions

Following the March 20, 2026 addition of five Apple, Craft CMS, and Laravel Livewire vulnerabilities to the KEV catalog, CISA required Federal Civilian Executive Branch agencies to remediate them by April 3, 2026 under BOD 22-01. The action formalized the federal response to the newly listed actively exploited flaws.

CISA adds Five Vulnerabilities to KEV Catalog- March 20, 2026 - TheCyberThrone

CISA adds five more exploited flaws affecting Apple, Craft CMS, and Laravel

On March 20, 2026, CISA announced another KEV catalog expansion, adding five newly exploited vulnerabilities affecting Apple multiple products, Craft CMS, and Laravel Livewire. The listed issues included buffer overflow, improper locking, and code injection flaws.

Mar 6, 20263mo ago

Google links Apple iOS flaws to Coruna exploit kit activity

Google Threat Intelligence Group attributed exploitation of some Apple vulnerabilities later added to CISA's KEV catalog to the Coruna (aka CryptoWaters) iOS exploit kit. GTIG said the kit targeted iPhones running iOS 13.0 through 17.2.1 and was used first in targeted campaigns and later more broadly by multiple tracked clusters.

Mar 5, 20263mo ago

CISA sets March 26 deadline for federal remediation of March 5 KEV additions

Under Binding Operational Directive 22-01, CISA required Federal Civilian Executive Branch agencies to remediate the five vulnerabilities added on March 5 by March 26, 2026. CISA also urged non-federal organizations to prioritize remediation of the newly listed KEV items.

CISA KEV catalog update raises total listed vulnerabilities to 1,536

CISA's KEV data repository was updated from catalog version 2026.03.04 to 2026.03.05, increasing the total number of listed vulnerabilities from 1,531 to 1,536. The update reflected the five newly added Apple, Hikvision, and Rockwell entries.

CISA adds five Apple, Hikvision, and Rockwell flaws to KEV

On March 5, 2026, CISA added five actively exploited vulnerabilities affecting Apple products, Hikvision IP cameras, and Rockwell Automation products to its Known Exploited Vulnerabilities catalog. The additions included improper authentication, insufficiently protected credentials, integer overflow, and use-after-free issues.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

50 LINKEDOpen in app
Threat actors
3 linked
SOURCE COVERAGE

Sources

13 references tracked. Mallory keeps watching after this page renders.

13 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

CISA Adds Five Actively Exploited Vulnerabilities to the KEV Catalog | Mallory