Active Exploitation Watchlist + Notable CVEs
| CVE | Product | Severity | Status | Action |
|---|---|---|---|---|
| CVE-2026-20131 | Cisco Secure Firewall Management Center / Security Cloud Control | Critical (CVSS 10.0) | Actively exploited; Interlock ransomware since Jan 26, 2026; CISA KEV March 19 | Patch immediately; restrict FMC web interface from public internet; hunt for PowerShell anomalies |
| CVE-2026-27065 | Cisco Firewall Management Center | Critical | CISA Emergency Directive March 21; RCE; active exploitation confirmed | Emergency patch; federal deadline was March 22; private sector: patch now |
| CVE-2025-66376 | Zimbra Collaboration Suite Classic UI | High | Actively exploited by APT28 (Operation GhostMail); CISA KEV March 18; federal deadline April 1 | Upgrade to ZCS 10.0.18 or 10.1.13; audit all accounts for "ZimbraWeb" app-specific passwords and revoke; enable SOAP API monitoring |
| CVE-2026-20963 | Microsoft SharePoint Server | Critical (CVSS 9.8) | Actively exploited; deserialization RCE; CISA KEV March 19 | Apply January Patch Tuesday fix; restrict SharePoint external access; review logs for unauthorized code execution |
| CVE-2026-3909 | Google Chrome / Skia Graphics Engine | High | Actively exploited (KEV); drive-by via malicious HTML; federal patch deadline March 27 | Update Chrome to 142.0.7250.0+; patch Android, ChromeOS, Flutter apps |
| CVE-2026-3910 | Google Chromium V8 JavaScript Engine | High | Actively exploited (KEV); affects Chrome, Edge, Opera; sandbox escape chains observed | Update all Chromium-based browsers immediately; enterprise: force update via policy |
The Edge
The week's signal, stripped of noise.
Three threads ran in parallel this week, and they're converging into something nobody's governance frameworks are ready for. The Iran conflict produced a 245% cyber attack surge in two weeks (not from state actors deploying sophisticated zero-days, but from criminals opportunistically riding geopolitical chaos with stolen credentials and legitimate admin tools. Meanwhile, APT28 demonstrated a zero-click email exploit that makes the entire "security awareness training" industry look quaint. And Interlock sat inside Cisco's firewall management infrastructure for 36 days) blind to defenders, invisible to the tools defenders trust. This is the new baseline.
On the AI side, the White House released four pages of legislative intent and called it a framework. The EU scheduled two days of hearings. These are not comparable activities. One is a positioning document written for a news cycle; the other is the machinery of enforcement grinding into motion. Global enterprises hedging on US federal preemption while the EU moves toward actual enforcement deadlines are going to find themselves wrong in the most expensive possible way.
The meta-signal across both domains: the tools organizations have trusted (EDR, encrypted messaging apps, firewall perimeters, supply chain security scanners) are all being actively weaponized or bypassed this week. Not theoretically. Right now. The question isn't whether your defenses are configured correctly. It's whether the tools themselves are still on your side.