Monthly Vuln Summary 2026-03 (26)

In-the-Wild CVE Review · 2026-03

26 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).

本月收录

  • CVE-2026-3055 — 0.0 — Citrix NetScaler — Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configure… [KEV]
  • CVE-2025-53521 — 0.0 — F5 BIG-IP — F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution. [KEV]
  • CVE-2026-33634 — 0.0 — Aquasecurity Trivy — Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH k… [KEV]
  • CVE-2026-33017 — 0.0 — Langflow Langflow — Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication. [KEV]
  • CVE-2025-32432 — 0.0 — Craft CMS Craft CMS — Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code. [KEV]
  • CVE-2025-54068 — 0.0 — Laravel Livewire — Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios. [KEV]
  • CVE-2025-43510 — 0.0 — Apple Multiple Products — Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory share… [KEV]
  • CVE-2025-43520 — 0.0 — Apple Multiple Products — Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system terminati… [KEV]
  • CVE-2025-31277 — 0.0 — Apple Multiple Products — Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may l… [KEV]
  • CVE-2026-20131 — 0.0 — Cisco Secure Firewall Management Center (FMC) — Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the w… [KEV] [RANSOMWARE]
  • CVE-2025-66376 — 0.0 — Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives… [KEV]
  • CVE-2026-20963 — 0.0 — Microsoft SharePoint — Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. [KEV]
  • CVE-2025-47813 — 0.0 — Wing FTP Server Wing FTP Server — Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie. [KEV]
  • CVE-2026-3910 — 0.0 — Google Chromium V8 — Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code in… [KEV]
  • CVE-2026-3909 — 0.0 — Google Skia — Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affe… [KEV]
  • CVE-2025-68613 — 0.0 — n8n n8n — n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution. [KEV]
  • CVE-2021-22054 — 0.0 — Omnissa Workspace One UEM — Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network acc… [KEV]
  • CVE-2025-26399 — 0.0 — SolarWinds Web Help Desk — SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine. [KEV] [RANSOMWARE]
  • CVE-2026-1603 — 0.0 — Ivanti Endpoint Manager (EPM) — Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific… [KEV]
  • CVE-2017-7921 — 0.0 — Hikvision Multiple Products — Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive inf… [KEV]
  • CVE-2021-22681 — 0.0 — Rockwell Multiple Products — Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to ve… [KEV]
  • CVE-2023-43000 — 0.0 — Apple Multiple Products — Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption. [KEV]
  • CVE-2021-30952 — 0.0 — Apple Multiple Products — Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbi… [KEV]
  • CVE-2023-41974 — 0.0 — Apple iOS and iPadOS — Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges. [KEV]
  • CVE-2026-22719 — 0.0 — Broadcom VMware Aria Operations — Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrar… [KEV]
  • CVE-2026-21385 — 0.0 — Qualcomm Multiple Chipsets — Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation. [KEV]

Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.