CISA Adds Aqua Security Trivy Scanner Flaw to KEV Catalog

The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Aqua Security’s Trivy scanner to its Known Exploited Vulnerabilities (KEV) catalog, raising urgent concerns across DevOps and cloud security teams.

The flaw, tracked as CVE-2026-33634, is already being actively exploited and poses a serious supply chain risk due to Trivy’s widespread use in CI/CD environments.

Trivy is a popular open-source vulnerability scanner used to detect security issues in container images, file systems, and repositories.

Because it is deeply integrated into modern development pipelines, any compromise of the tool can expose sensitive systems at scale.

CISA’s inclusion of this flaw in the KEV catalog confirms that attackers are actively leveraging it in real-world scenarios.

At the core of CVE-2026-33634 is a malicious code insertion vulnerability, classified under CWE-506. This type of weakness involves hidden or embedded code that can be triggered by threat actors to execute unauthorized actions.

In this case, exploitation allows attackers to bypass standard access controls and gain deep visibility into CI/CD environments.

Once triggered, the malicious code enables attackers to scan memory spaces and extract operational data.

This includes highly sensitive information such as development tokens, SSH keys, cloud infrastructure credentials, and backend database passwords.

Given Trivy’s elevated privileges during scanning processes, a successful exploit effectively grants attackers access to critical components of the software development lifecycle.

The potential impact is significant. Compromising a CI/CD pipeline can allow attackers to manipulate builds, inject malicious code into software releases, or maintain persistent access within development environments.

This makes the vulnerability particularly attractive to advanced persistent threat (APT) groups and initial access brokers who specialize in gaining footholds within high-value targets.

Although there is no confirmed evidence yet linking CVE-2026-33634 to ransomware campaigns, its data exfiltration capabilities make it a strong candidate for future exploitation in financially motivated attacks.

Security researchers warn that supply chain attacks involving developer tools are becoming increasingly common, amplifying the risk associated with such vulnerabilities.

CISA officially added the vulnerability to its KEV catalog on March 26, 2026. The KEV catalog serves as a prioritized list of vulnerabilities known to be actively exploited, helping organizations focus their remediation efforts.

Along with the listing, CISA issued a strict remediation deadline of April 9, 2026, for Federal Civilian Executive Branch (FCEB) agencies.

Organizations using Trivy are strongly advised to follow vendor-provided mitigation guidance immediately.

Security teams should also align with Binding Operational Directive (BOD) 22-01, which outlines requirements for addressing known exploited vulnerabilities.

In cases where patches or mitigations are not yet available, CISA recommends discontinuing the use of Trivy until the environment can be secured.

This highlights the severity of the threat and the importance of preventing further exposure.

As CI/CD pipelines remain a critical backbone of modern software delivery, this incident underscores the growing risks associated with trusted security tools becoming attack vectors themselves.

Organizations must continuously monitor and secure their development ecosystems to mitigate evolving supply chain threats.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories