CISA's list that day
20 March 2026
On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in Apple Multiple Products, Craft CMS and Laravel Livewire. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-32432Code Injection | Craft CMS Craft CMS | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2025-54068Code Injection | Laravel Livewire | Patch this weekEPSS 0.97 | 0.97 | ||
| CVE-2025-31277Buffer Overflow | Apple Multiple Products | Patch soon | 0.02 | ||
| CVE-2025-43520Classic Buffer Overflow | Apple Multiple Products | Patch soon | 0.00 | ||
| CVE-2025-43510Improper Locking | Apple Multiple Products | Patch soon | 0.00 |