PatchSiren

Aquasecurity CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Aquasecurity CVE published 2026-03-26

CVE-2026-33634

CVE-2026-33634 is a CISA Known Exploited Vulnerability affecting Aqua Security Trivy. The available official records describe it as an embedded malicious code vulnerability and note that it may represent a supply-chain compromise that can affect multiple products and environments. Because CISA added it to the KEV catalog, defenders should treat it as an active risk requiring prompt mitigation based on ven [truncated]