CISA Adds Apple WebKit, Kernel, Craft CMS, and Laravel Livewire Flaws to KEV Catalog
Summary
Hide ▲
Show ▼
CISA added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on March 21, 2026, requiring federal agencies to patch them by April 3, 2026. The vulnerabilities include three Apple issues (CVE-2025-31277, CVE-2025-43510, CVE-2025-43520), a critical Craft CMS flaw (CVE-2025-32432), and a Laravel Livewire issue (CVE-2025-54068), all under active exploitation. The Apple flaws are linked to the DarkSword iOS exploit kit, while the Craft CMS and Laravel Livewire bugs are tied to campaigns by MuddyWater and other threat actors. Exploitation of CVE-2025-32432 as a zero-day since February 2025 has been attributed to intrusion set Mimo (aka Hezb), deploying cryptocurrency miners and residential proxyware. CVE-2025-54068 is associated with Iranian state-sponsored group MuddyWater (aka Boggy Serpens), which has targeted diplomatic, energy, maritime, and financial sectors globally.
Timeline
-
21.03.2026 10:25 1 articles · 2h ago
CISA mandates patching of five KEV catalog vulnerabilities by April 3, 2026
CISA added CVE-2025-31277, CVE-2025-43510, CVE-2025-43520 (Apple), CVE-2025-32432 (Craft CMS), and CVE-2025-54068 (Laravel Livewire) to the KEV catalog on March 21, 2026, requiring federal agencies to patch all by April 3, 2026. The move follows confirmed exploitation of these flaws in campaigns leveraging the DarkSword exploit kit and activity attributed to intrusion set Mimo and Iranian state-sponsored actor MuddyWater.
Show sources
- CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026 — thehackernews.com — 21.03.2026 10:25
Information Snippets
-
CVE-2025-31277 (CVSS 8.8) is a memory corruption flaw in Apple WebKit that enables arbitrary code execution when processing malicious web content (patched in July 2025).
First reported: 21.03.2026 10:251 source, 1 articleShow sources
- CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026 — thehackernews.com — 21.03.2026 10:25
-
CVE-2025-43510 (CVSS 7.8) and CVE-2025-43520 (CVSS 8.8) are memory corruption vulnerabilities in Apple’s kernel component allowing malicious applications to manipulate shared memory or write to kernel memory (patched in December 2025).
First reported: 21.03.2026 10:251 source, 1 articleShow sources
- CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026 — thehackernews.com — 21.03.2026 10:25
-
CVE-2025-32432 (CVSS 10.0) is a critical code injection flaw in Craft CMS enabling remote attackers to execute arbitrary code (patched in April 2025).
First reported: 21.03.2026 10:251 source, 1 articleShow sources
- CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026 — thehackernews.com — 21.03.2026 10:25
-
CVE-2025-54068 (CVSS 9.8) is a Laravel Livewire vulnerability allowing unauthenticated remote command execution in specific scenarios (patched in July 2025).
First reported: 21.03.2026 10:251 source, 1 articleShow sources
- CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026 — thehackernews.com — 21.03.2026 10:25
-
CVE-2025-31277, CVE-2025-43510, and CVE-2025-43520 are exploited via the DarkSword iOS exploit kit to deploy malware families GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER for data theft.
First reported: 21.03.2026 10:251 source, 1 articleShow sources
- CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026 — thehackernews.com — 21.03.2026 10:25
-
CVE-2025-32432 has been exploited as a zero-day since February 2025 by intrusion set Mimo (aka Hezb), which has also deployed cryptocurrency miners and residential proxyware.
First reported: 21.03.2026 10:251 source, 1 articleShow sources
- CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026 — thehackernews.com — 21.03.2026 10:25
-
CVE-2025-54068 is exploited by MuddyWater (aka Boggy Serpens), an Iranian state-sponsored group targeting diplomatic and critical infrastructure sectors across the Middle East, maritime, finance, and other regions.
First reported: 21.03.2026 10:251 source, 1 articleShow sources
- CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026 — thehackernews.com — 21.03.2026 10:25