Known exploited
Aquasecurity
CVE published 2026-03-26
CVE-2026-33634
CVE-2026-33634 is a CISA Known Exploited Vulnerability affecting Aqua Security Trivy. The available official records describe it as an embedded malicious code vulnerability and note that it may represent a supply-chain compromise that can affect multiple products and environments. Because CISA added it to the KEV catalog, defenders should treat it as an active risk requiring prompt mitigation based on ven [truncated]