U.S. CISA adds Apple, Rockwell, and Hikvision flaws to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-7921 | Improper Authentication Bypass in Multiple Hikvision Products CVE-2017-7921 is an improper authentication flaw (CWE-287) in multiple Hikvision products that allows an attacker to defeat the devices' authentication checks. It is triggered by sending specially crafted requests to an affected device, causing it to treat the attacker as an authenticated user. A successful attacker gains privilege escalation on the device and access to sensitive information. Any organization running affected Hikvision products, particularly devices reachable from the internet, is affected; the source data does not specify the individual models or firmware version ranges. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-03-05, confirming exploitation in the wild (ransomware use unknown), and EPSS assigns a ~100% probability of exploitation within 30 days. Do: Upgrade affected Hikvision devices to vendor-fixed firmware per Hikvision's security advisories (the data here does not name specific fixed versions), and follow CISA's required actions or BOD 22-01 guidance if applicable. Reduce exposure by removing affected devices from direct internet access and restricting the management interface to trusted networks. Check device logs and configurations for signs of unauthenticated or unauthorized access. | 9.8 | 100% | KEV |
| mass~1,000,000+ deployed devices, with hundreds of thousands internet-exposed | |
| CVE-2021-22681 | Authentication Bypass in Rockwell Automation Studio 5000 Logix Designer and Logix PLCs Rockwell Automation's Studio 5000 Logix Designer (versions 21 and later) and RSLogix 5000 (versions 16 through 20) use a shared key to verify that they are communicating with genuine Allen-Bradley Logix controllers, and an unauthenticated remote attacker can bypass this verification mechanism (CWE-522, insufficient protection of credentials). The attack requires only network access to the affected software or controllers - no credentials, no user interaction, and no special conditions (CVSS 3.1: 9.8). By bypassing the verification, an attacker can authenticate to CompactLogix, ControlLogix, DriveLogix, Compact GuardLogix, GuardLogix and SoftLogix controllers and interact with the PLCs, potentially tampering with industrial processes. Any deployment running the affected engineering software versions with the listed Logix controller families is in scope, which spans a very large share of Rockwell's installed base. CISA added this flaw to its Known Exploited Vulnerabilities catalog on 2026-03-05 (ransomware use unknown), and EPSS puts the 30-day exploitation probability at roughly 64%; no public proof-of-concept is known. Do: Apply mitigations per Rockwell's instructions - the vendor has advised disconnecting internet-facing connections, so remove internet exposure from affected controllers and engineering workstations and segment OT networks. Follow applicable CISA BOD 22-01 guidance, and inventory for Studio 5000 Logix Designer v21+ or RSLogix 5000 v16-20 used with the listed controllers; upgrade per vendor guidance or discontinue use if mitigations are unavailable. | 9.8 | 64% | KEV |
| massroughly 1 million or more Logix controller installations (tens of thousands likely internet-exposed) | |
| CVE-2021-30952 | CVE-2021-30952: Integer Overflow in Apple Safari/WebKit Allows Arbitrary Code Execution CVE-2021-30952 is an integer overflow (CWE-190) in the WebKit web engine used across Apple's platforms — the same engine shipped as WebKitGTK and WPE WebKit on Linux — which Apple addressed with improved input validation. An attacker triggers it by persuading a user to process maliciously crafted web content, such as loading an attacker-controlled web page, and successful exploitation leads to arbitrary code execution on the victim's device (CVSS 3.1: 7.8 high, with a local attack vector requiring user interaction). All users of unpatched affected platforms are exposed: iOS/iPadOS before 15.2, macOS Monterey before 12.1, Safari before 15.2, tvOS before 15.2, and watchOS before 8.3, plus Fedora/Debian systems running unpatched WebKitGTK/WPE WebKit. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-03-05 (ransomware use: unknown), and Google threat intelligence documented it as part of the 'Coruna' iOS exploit kit — 23 exploits across five chains, used for financial crime and targeting devices on older iOS versions such as iOS 13. EPSS assigns a 7.0% probability of exploitation within 30 days (94th percentile). Do: Upgrade to iOS/iPadOS 15.2, macOS Monterey 12.1, Safari 15.2, tvOS 15.2, and watchOS 8.3; devices on older iOS branches (e.g., iOS 13, targeted by the Coruna exploit kit) should immediately apply Apple's emergency fixes for those versions. On Fedora and Debian, pull the latest WebKitGTK/WPE WebKit security updates through the distro package channels. Federal agencies must meet the BOD 22-01 remediation deadline for this KEV entry, and should inventory for Apple devices that cannot reach a patched version and replace or isolate them. | 7.8 | 7% | KEV PoC |
| mass≈1 billion+ Apple devices (iOS/iPadOS/macOS/tvOS/watchOS/Safari install base), with practical residual exposure concentrated in legacy iPhones/iPads on old iOS… | |
| CVE-2023-41974 | Use-After-Free Kernel Code Execution Flaw in Apple iOS and iPadOS CVE-2023-41974 is a use-after-free (CWE-416) memory-corruption vulnerability in Apple iOS and iPadOS that was addressed with improved memory management. It is triggered locally when an application on the device exercises the affected code path; the CVSS vector (AV:L/UI:R) indicates the attacker needs code running on the device and user interaction, but no network access or privileges. A successful exploit allows an app to execute arbitrary code with kernel privileges, giving the attacker full control over the affected iPhone or iPad. Anyone running iOS/iPadOS versions prior to iOS 17/iPadOS 17, including legacy 15.x devices prior to 15.8.7, is affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-03-05, and public references tie it to the spy-grade 'Coruna' iOS exploit kit (23 exploits across five chains) used for financial crime, confirming exploitation in the wild. Do: Update iPhones to iOS 17 and iPads to iPadOS 17, or apply the iOS 15.8.7 / iPadOS 15.8.7 emergency updates on legacy hardware that cannot run 17; inventory your fleet for devices on older builds and prioritize them, since the Coruna exploit kit reportedly targets older iOS versions. Until patched, avoid installing apps from untrusted sources, as exploitation requires running a malicious app. Federal agencies must meet the applicable BOD 22-01 required-action deadline for this KEV entry. | 7.8 | 1% | KEV PoC |
| mass≈1 billion+ devices in scope | |
| CVE-2023-43000 | Use-After-Free in Apple WebKit: Safari, iOS, iPadOS, macOS (CVE-2023-43000) CVE-2023-43000 is a use-after-free vulnerability (CWE-416) in Apple's web content processing (WebKit) that was addressed with improved memory management. It is triggered when a device processes maliciously crafted web content, which per the CVSS vector requires user interaction such as visiting an attacker-controlled page. Successful exploitation causes memory corruption, and the high confidentiality, integrity, and availability scores indicate an attacker can likely gain code execution or data compromise on the target device. Any unpatched user of Safari, iOS, iPadOS, or macOS macOS versions earlier than the fixed releases is affected, including older iOS devices that Apple has now issued emergency updates for. The flaw is being actively exploited: it was added to the CISA Known Exploited Vulnerabilities catalog on 2026-03-05, a public PoC reference ties it to the Coruna iOS exploit kit (a spy-grade kit with 23 exploits used for financial crime), and EPSS estimates a 3.9% chance of exploitation in the next 30 days (90th percentile). Do: Update affected systems to macOS Ventura 13.5, iOS/iPadOS 16.6, Safari 16.6, or, for older devices still on iOS 15, iOS/iPadOS 15.8.7. Federal agencies under BOD 22-01 must apply vendor mitigations by the KEV deadline or discontinue use of affected products. Because exploitation requires user interaction with crafted web content, prioritize patching internet-facing and at-risk mobile fleets, and warn users to avoid untrusted links as an interim measure. | 8.8 | 4% | KEV PoC |
| mass≈1 billion+ devices and users (Apple's active iPhone/iPad/Mac install base plus Safari users worldwide) |
Full article520 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple, Rockwell, and Hikvision flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Rockwell, and Hikvision flaws to its Known Exploited Vulnerabilities (KEV) catalog.
Below are the flaws added to the catalog:
- CVE-2023-43000 (CVSS score of 8.8) Apple Multiple products Use-After-Free Vulnerability
- CVE-2017-7921 (CVSS score of 9.8) Hikvision Multiple Products Improper Authentication Vulnerability
- CVE-2021-22681 (CVSS score of 9.8) Rockwell Multiple Products Insufficient Protected Credentials Vulnerability
- CVE-2021-30952 (CVSS score of 8.8) Apple Multiple Products Integer Overflow or Wraparound Vulnerability
- CVE-2023-41974 (CVSS score of 7.8) Apple iOS and iPadOS Use-After-Free Vulnerability
CVE-2023-43000 is a use-after-free issue in the WebKit component. Apple addressed the vulnerability with improved memory management in macOS Ventura 13.5, iOS 16.6, iPadOS 16.6, and Safari 16.6. The flaw could allow maliciously crafted web content to trigger memory corruption.
The second flaw added to the catalog, tracked as CVE-2017-7921, is an improper authentication vulnerability that affects multiple Hikvision IP camera series running older firmware versions. The flaw occurs when the system fails to correctly verify user credentials, potentially allowing attackers to bypass authentication, escalate privileges, and gain unauthorized access to sensitive data or device controls.
The third flaw added to the catalog, tracked as CVE-2021-22681, impacts Rockwell Automation Studio 5000 Logix Designer and RSLogix 5000, allowing an unauthenticated attacker to bypass the key-based verification used to authenticate with industrial controllers. By exploiting this flaw, attackers could impersonate trusted systems and communicate with affected controllers, potentially compromising industrial automation environments.
CISA also added Apple vulnerabilities CVE-2021-30952 and CVE-2023-41974 to the catalog after Google’s Threat Intelligence Group reported the discovery of a powerful new iOS exploit kit called Coruna (also known as CryptoWaters) that targets Apple iPhones running iOS versions 13.0 through 17.2.1. The kit includes five full exploit chains and a total of 23 exploits, including the above Apple issues.
While highly capable against iPhones running iOS 13.0 through 17.2.1versions, Coruna is ineffective against the latest iOS release, according to Google.
GTIG tracked the use of the exploit in highly targeted attacks by a surveillance vendor’s customer, in Ukrainian watering hole campaigns by UNC6353, and later in broad-scale attacks by Chinese financial threat actor UNC6691, showing an active market for “second-hand” zero-day exploits. Multiple threat actors now reuse and adapt these advanced techniques for new vulnerabilities.
GTIG shared the findings to raise awareness and protect users, adding identified domains to Safe Browsing.
Initial discovery occurred in February 2025 when GTIG captured a previously unseen JavaScript framework delivering an iOS exploit chain from a surveillance vendor’s customer.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerabilities by March 26, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/189005/security/u-s-cisa-adds-apple-rockwell-and-hikvision-flaws-to-its-known-exploited-vulnerabilities-catalog.html