CISA: Apple, Craft CMS, Laravel Flaws in KEV. Patch by 4/3/26 Mandated.
Mar 21, 2026 // 11:34 - Niko Dunn


On Friday, the U.S. agency responsible for cybersecurity, CISA, added five security weaknesses in products from Apple, Craft CMS, and Laravel Livewire to its list of actively exploited vulnerabilities (KEV), requiring federal organizations to apply patches by April 3, 2026.

The vulnerabilities that are being actively exploited are listed below –

  • CVE-2025-31277 (CVSS score: 8.8) – An Apple WebKit issue that could cause memory problems when processing malicious web content. (Addressed in July 2025)
  • CVE-2025-43510 (CVSS score: 7.8) – An Apple kernel flaw that could let a malicious application cause unforeseen memory changes between processes. (Addressed in December 2025)
  • CVE-2025-43520 (CVSS score: 8.8) – An Apple kernel flaw that could allow a malicious application to cause unexpected system crashes or write to the kernel’s memory. (Addressed in December 2025)
  • CVE-2025-32432 (CVSS score: 10.0) – A Craft CMS flaw that could let a remote attacker run arbitrary code. (Addressed in April 2025)
  • CVE-2025-54068 (CVSS score: 9.8) – A Laravel Livewire flaw allowing unauthenticated attackers to remotely execute commands in certain situations. (Addressed in July 2025)

The Apple vulnerabilities were added after reports from Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout detailed an iOS exploit named DarkSword, which uses these, alongside three other vulnerabilities, to spread malware such as GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER to steal data.

Orange Cyberdefense SensePost reported that CVE-2025-32432 was likely exploited as a zero-day by unknown attackers starting in February 2025. Since then, a threat group known as Mimo (also called Hezb) has used this vulnerability to install cryptocurrency miners and residential proxyware.

Completing the list is CVE-2025-54068, which the Ctrl-Alt-Intel Threat Research team recently highlighted as being exploited by the Iranian government-backed hacking group, MuddyWater (also called Boggy Serpens).

Palo Alto Networks Unit 42 reported earlier in the week that this group consistently targets diplomatic and critical infrastructure, including energy, maritime, and finance sectors, in the Middle East and other key locations around the globe.

“While social engineering continues to be their main tactic, the group is improving its technical skills,” Unit 42 stated. “Their toolkit includes advanced malware with built-in anti-analysis features for long-term access. This combination of social engineering and rapidly developed tools makes them a significant threat.”

“To manage its extensive social engineering campaigns, Boggy Serpens uses a custom, web-based platform,” Unit 42 mentioned. “This tool allows operators to automate mass email delivery while maintaining precise control over sender information and recipient lists.”

This group, linked to the Iranian Ministry of Intelligence and Security (MOIS), primarily focuses on cyber espionage but has also been connected to disruptive operations targeting the Technion Israel Institute of Technology by using the DarkBit ransomware disguise.

A key aspect of MuddyWater’s methods involves using compromised accounts from government and corporate organizations in their phishing attacks and exploiting trusted relationships to bypass security systems and deliver malware. 

In an ongoing attack against a national marine and energy company in the U.A.E. from August 16, 2025, to February 11, 2026, the threat actor reportedly launched four separate attack waves, deploying several malware families, including GhostBackDoor and Nuso (also known as HTTP_VIP). Other notable tools in their arsenal include UDPGangster and LampoRAT (also known as CHAR).

“Boggy Serpens’ recent actions demonstrate a more sophisticated threat profile, as the group combines its established methods with enhanced techniques for maintaining operational access,” Unit 42 concluded. “By broadening its development efforts to include newer coding languages like Rust and AI-assisted processes, the group is creating multiple paths to ensure the resilience needed to maintain a high operational pace.”

#4/3/26  #apple  #cisa  #cms,  #craft  #flaws  #kev  #laravel  #mandated.  #news  #patch   —   News