CISA

CISA Adds Seven Known Exploited Vulnerabilities to Catalog

From Cybersecurity and Infrastructure Security Agency ↗

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

CVE-2012-1854 Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability

CVE-2020-9715 Adobe Acrobat Use-After-Free Vulnerability

CVE-2023-21529 Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

CVE-2023-36424 Microsoft Windows Out-of-Bounds Read Vulnerability

CVE-2025-60710 Microsoft Windows Link Following Vulnerability

CVE-2026-21643 Fortinet SQL Injection Vulnerability

CVE-2026-34621 Adobe Acrobat and Reader Prototype Pollution Vulnerability

These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.

Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities establishe...