U.S. CISA adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-58136 | Regression of Yii 2 Behavior-Attachment Flaw (CVE-2024-4990) Enables In-the-Wild RCE Yii 2 versions before 2.0.52 mishandle the attaching of behaviors defined with an __class array key, reintroducing the flaw fixed for CVE-2024-4990, an unauthenticated remote code execution issue (CWE-424, improper protection of alternate path). The defect is triggered remotely without authentication when a vulnerable application attaches behaviors this way, giving an attacker high-impact code execution (CVSS 9.8). Any application built on a vulnerable Yii 2 release is affected, most prominently Craft CMS sites, which were the target of an observed in-the-wild campaign between February and April 2025. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-02, carries an 84.6% EPSS probability of exploitation within 30 days, and a public SensePost writeup documents the active Craft CMS exploitation campaign. The top headline reports that hundreds of servers were likely compromised in that campaign. Do: Upgrade Yii 2 to version 2.0.52 or later; Craft CMS operators should immediately update Craft CMS to its patched release that bundles fixed Yii, and confirm the resolved framework version on the system. Because the campaign ran from February through April 2025, review web/application logs and hosted files for indicators from the SensePost writeup, treating any unpatched internet-facing Yii 2 or Craft CMS host as likely compromised. Federal agencies must apply the KEV required action (vendor mitigations or BOD 22-01 guidance) by the CISA deadline. | 9.8 | 88% | KEV PoC |
| large≈100,000+ internet-facing applications built on Yii 2 (including tens of thousands of Craft CMS sites) | |
| CVE-2025-31277 | Buffer Overflow in Apple WebKit (Safari, iOS/iPadOS, macOS, WebKitGTK, WPE) CVE-2025-31277 is a memory-handling flaw (buffer overflow, CWE-119/CWE-120) in Apple's WebKit engine, the component that renders web content in Safari and in webviews across Apple platforms. It is triggered when a user processes maliciously crafted web content, typically by visiting an attacker-controlled page, causing memory corruption that can compromise the rendering process, with CVSS 3.1 scoring high impact to confidentiality, integrity and availability (8.8) via a network vector requiring user interaction but no privileges. Everyone running WebKit is affected: Safari users and devices on iOS/iPadOS, macOS Sequoia, tvOS, visionOS and watchOS prior to the fixed releases, plus Linux users of WebKitGTK and WPE WebKit as shipped with Red Hat Enterprise Linux (including the AUS and ELS channels). Exploitation is confirmed in the wild: CISA added the bug to its Known Exploited Vulnerabilities catalog on 2026-03-20 (ransomware linkage unknown) with a BOD 22-01 remediation deadline of 2026-04-03, and contemporaneous reporting describes 'DarkSword', an iOS exploit kit chaining multiple Apple flaws, reportedly including zero-days, in global attacks, possibly including this bug. No public proof-of-concept is known, and fixes shipped in Safari 18.6, iOS/iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6 and watchOS 11.6. Do: Upgrade Safari to 18.6 or later and apply the corresponding OS updates: iOS/iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6 and watchOS 11.6; on Red Hat Enterprise Linux (including AUS/ELS) install Red Hat's updated WebKitGTK/WPE WebKit packages. Organizations subject to CISA BOD 22-01 must patch or mitigate by the April 3, 2026 deadline. Until patched, restrict WebKit-based browsing and webviews on affected devices to trusted content, since exploitation requires loading maliciously crafted web content. | 8.8 | 2% | KEV |
| mass≈1 billion+ users/devices (WebKit ships on essentially every active iPhone, iPad, Mac, Apple TV, Apple Watch and Vision Pro; the RHEL WebKitGTK/WPE WebKit… | |
| CVE-2025-32432 | Code Injection Enables Remote Code Execution in Craft CMS Craft CMS contains a code injection vulnerability (CWE-94) that allows a remote attacker to execute arbitrary code on affected servers. CISA's listing does not specify the exact attack path or authentication requirements, but the flaw is remotely triggerable and grants arbitrary code execution, which typically means full compromise of the web server and a foothold for follow-on activity such as ransomware (ransomware use is not yet confirmed). Any organization running a Craft CMS instance is in scope, including internet-facing content sites and deployments where the Craft admin panel is reachable from the internet. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-20, confirming exploitation in the wild, and EPSS assigns a 99.8% probability of exploitation within 30 days (100th percentile), although no public proof-of-concept is known. No CVSS score has been published yet, so defenders should treat the flaw as urgent given the KEV listing and near-certain EPSS likelihood. Do: Apply the patched Craft CMS release per the vendor's security advisory referenced in CISA's KEV entry (specific fixed version numbers are not provided in the source data), prioritizing internet-exposed instances, and U.S. federal agencies should follow BOD 22-01 requirements for KEV-listed flaws. Until patched, restrict network access to the Craft CMS control panel/admin interface and review web and application logs for signs of code injection or unexpected process execution, since exploitation in the wild is confirmed while ransomware use remains unknown. Given the 99.8% EPSS score and KEV listing, treat discovery and patching of all Craft CMS instances, including headless deployments, as an urgent, time-boxed task. | 10.0 | 100% | KEV PoC |
| mass≈100,000–200,000+ live Craft CMS sites (order of magnitude: ~10^5 internet-facing deployments) | |
| CVE-2025-43510 +1 in the same advisory: …43520 | Improper Locking Memory Corruption in Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS CVE-2025-43510 is an improper locking flaw (CWE-667) in Apple's operating systems that leads to memory corruption, addressed by improved lock state checking. It is triggered locally: a malicious application already running on the device can cause unexpected changes in memory shared between processes, with the CVSS vector (AV:L, UI:R) indicating user interaction is required but no privileges needed beforehand. Successful exploitation could corrupt or expose cross-process shared memory, yielding high impacts on confidentiality, integrity, and availability (CVSS 3.1 score 7.8), and such shared-memory corruption bugs in Apple's OSes are commonly leveraged as steps in chained attacks such as sandbox escapes. All users of iOS, iPadOS, macOS (Sonoma, Sequoia, and Tahoe branches), tvOS, visionOS, and watchOS on versions earlier than the fixed releases are affected. The vulnerability is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-20 with a federal patching deadline of April 3, 2026, and news reports describe an active iOS exploit kit ('DarkSword') using multiple Apple flaws, including zero-days, in global attacks. Do: Update to the fixed releases: iOS/iPadOS 18.7.2 or iOS/iPadOS 26.1; macOS Sonoma 14.8.2, Sequoia 15.7.2, or Tahoe 26.1; tvOS 26.1; visionOS 26.1; and watchOS 26.1. As a local attack vector, prioritize patching devices that install untrusted apps, and federal agencies must apply the fixes under BOD 22-01 by April 3, 2026 per the CISA KEV listing. Given reports of the DarkSword iOS exploit kit chaining multiple Apple flaws in active attacks, treat unpatched iPhones and iPads as high priority and verify OS versions across your fleet. | 7.8 group max | <1% | KEV |
| mass>1 billion active Apple devices across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS (essentially the entire unpatched active install base) | |
| CVE-2025-54068 | Unauthenticated Code Injection RCE in Laravel Livewire v3 CVE-2025-54068 is an improper hydration flaw (CWE-94 code injection) in Livewire v3, a full-stack framework for Laravel, that allows unauthenticated attackers to achieve remote command execution in specific scenarios. The flaw is triggered when a Livewire component is mounted and configured in a particular way and receives certain component property updates, with no authentication or user interaction required. A successful attacker gains code execution on the server hosting the affected Laravel application. Only Livewire v3 up to and including v3.6.3 is affected; earlier major versions are not impacted, and the issue is fixed in v3.6.4. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog (added 2026-03-20, patching deadline 2026-04-03), indicating confirmed exploitation in the wild, and EPSS assigns a 96.5% probability of exploitation within 30 days. Do: Upgrade Livewire to v3.6.4 or later immediately, as no workarounds are available. Audit Laravel applications for Livewire v3 usage and identify components mounted and configured in the vulnerable property-hydration pattern, prioritizing internet-facing apps. Federal agencies must apply vendor mitigations or discontinue use by the BOD 22-01 deadline of April 3, 2026. | 9.2 | 96% | KEV |
| large≈10,000–100,000 Laravel application deployments (the subset of Livewire v3 installs using the vulnerable component mounting/property-update configuration) |
Full article571 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities (KEV) catalog.
Below are the flaws added to the catalog:
- CVE-2025-31277 (CVSS score of 8.8) Apple Multiple Products Buffer Overflow Vulnerability
- CVE-2025-32432 (CVSS score of 10.0) Craft CMS Code Injection Vulnerability
- CVE-2025-43510 (CVSS score of 7.8) Apple Multiple Products Improper Locking Vulnerability
- CVE-2025-43520 (CVSS score of 8.8) Apple Multiple Products Classic Buffer Overflow Vulnerability
- CVE-2025-54068 (CVSS score of 9.8) Laravel Livewire Code Injection Vulnerability
CISA added the three Apple flaws (CVE-2025-31277, CVE-2025-43510, CVE-2025-43520) in the KEV catalog following reports from recent Google Threat Intelligence Group, iVerify, and Lookout about an iOS exploit kit called DarkSword. The kit targets these vulnerabilities, along with three other bugs, to deliver malware.
CISA also added a code injection issue, tracked as CVE-2025-32432, to its KeV catalog. In April 2025, Orange Cyberdefense’s CSIRT reported that threat actors exploited two vulnerabilities in Craft CMS to breach servers and steal data. Orange Cyberdefense’s CSIRT warned that threat actors chained two Craft CMS vulnerabilities in attacks in the wild. Orange experts discovered the flaws while investigating a server compromise. The two vulnerabilities, tracked as CVE-2025-32432 and CVE-2024-58136, are respectively a remote code execution (RCE) in Craft CMS and an input validation flaw in the Yii framework used by Craft CMS. According to a report published by SensePost, Orange Cyberdefense’s ethical hacking team, threat actors exploited the two vulnerabilities to breach servers and upload a PHP file manager. The attack began by exploiting the CVE-2025-32432 flaw: a crafted request included a “return URL” that was saved to a PHP session file.
Both vulnerabilities have been fixed; the flaw CVE-2025-32432 has been addressed with the release of versions 3.9.15, 4.14.15, and 5.6.17. The development team behind Yii addressed the issue with the release of Yii 2.0.52 in April. 9th, 2025.
The last vulnerability added to the CISA’s KeV catalog is CVE-2025-54068, which was linked to attacks by Iran-nexus APT MuddyWater, known for targeting diplomatic and critical sectors like energy and finance. The first MuddyWater campaign was observed in late 2017, when the APT group targeted entities in the Middle East.
Experts named the campaign ‘MuddyWater’ due to the difficulty in attributing a wave of attacks between February and October 2017, targeting entities in Saudi Arabia, Iraq, Israel, the United Arab Emirates, Georgia, India, Pakistan, Turkey, and the United States. Over the years, the group has evolved by adding new attack techniques to its arsenal and has also targeted European and North American countries.
The group’s victims are mainly in the telecommunications, government (IT services), and oil sectors.
In January 2022, US Cyber Command (USCYBERCOM) officially linked the MuddyWater APT group to Iran’s Ministry of Intelligence and Security (MOIS).
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerabilities by April 3, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/189776/security/u-s-cisa-adds-apple-laravel-livewire-and-craft-cms-flaws-to-its-known-exploited-vulnerabilities-catalog.html