CISA Adds Apple, Craft CMS and Laravel Flaws to KEV; Federal Patch Deadline April 3, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday placed five security defects that affect Apple, Craft CMS and Laravel Livewire into its Known Exploited Vulnerabilities (KEV) list, directing federal entities to install fixes by April 3, 2026.
Below are the vulnerabilities CISA flagged as being actively exploited, along with their CVSS ratings and remediation dates:
- CVE-2025-31277 (CVSS 8.8) – A flaw in Apple WebKit that can lead to memory corruption when the browser handles crafted web content. Apple addressed this issue in July 2025.
- CVE-2025-43510 (CVSS 7.8) – A kernel memory corruption issue in Apple’s operating system that could let a malicious app manipulate memory shared across processes. A patch was released in December 2025.
- CVE-2025-43520 (CVSS 8.8) – Another Apple kernel memory-corruption bug capable of causing unexpected system crashes or enabling writes to kernel memory; fixed by Apple in December 2025.
- CVE-2025-32432 (CVSS 10.0) – A critical code injection vulnerability in Craft CMS that permits remote code execution by attackers. This defect was corrected in April 2025.
- CVE-2025-54068 (CVSS 9.8) – A code injection issue in Laravel Livewire that, in certain contexts, allows unauthenticated actors to achieve remote command execution. The fix arrived in July 2025.