CISA's list that day
3 March 2026
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Qualcomm Multiple Chipsets and Broadcom VMware Aria Operations. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-22719Command Injection | Broadcom VMware Aria Operations | Patch soon | 0.18 | ||
| CVE-2026-21385Memory Corruption | Qualcomm Multiple Chipsets | Patch soon | 0.01 |