Skip to content

Commit aa20baf

Browse files
Update KEV: Fri Mar 20 00:19:21 UTC 2026
Signed-off-by: AboutCode Automation <[email protected]>
1 parent a95d06d commit aa20baf

1 file changed

Lines changed: 19 additions & 4 deletions

File tree

known_exploited_vulnerabilities.json

Lines changed: 19 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,24 @@
11
{
22
"title": "CISA Catalog of Known Exploited Vulnerabilities",
3-
"catalogVersion": "2026.03.18",
4-
"dateReleased": "2026-03-18T19:24:20.2811Z",
5-
"count": 1545,
3+
"catalogVersion": "2026.03.19",
4+
"dateReleased": "2026-03-19T15:13:53.6798Z",
5+
"count": 1546,
66
"vulnerabilities": [
7+
{
8+
"cveID": "CVE-2026-20131",
9+
"vendorProject": "Cisco",
10+
"product": "Secure Firewall Management Center (FMC)",
11+
"vulnerabilityName": "Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability",
12+
"dateAdded": "2026-03-19",
13+
"shortDescription": "Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.",
14+
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
15+
"dueDate": "2026-03-22",
16+
"knownRansomwareCampaignUse": "Known",
17+
"notes": "https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-fmc-rce-NKhnULJh ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-20131",
18+
"cwes": [
19+
"CWE-502"
20+
]
21+
},
722
{
823
"cveID": "CVE-2025-66376",
924
"vendorProject": "Synacor",
@@ -696,7 +711,7 @@
696711
{
697712
"cveID": "CVE-2018-14634",
698713
"vendorProject": "Linux",
699-
"product": "Kernal",
714+
"product": "Kernel",
700715
"vulnerabilityName": "Linux Kernel Integer Overflow Vulnerability",
701716
"dateAdded": "2026-01-26",
702717
"shortDescription": "Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalate their privileges on the system.",

0 commit comments

Comments
 (0)