CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2012-1854 | Insecure Library Loading (CWE-426) in Microsoft Visual Basic for Applications Microsoft Visual Basic for Applications (VBA) fails to fully specify the search path used when loading dynamic-link libraries, so applications embedding VBA may load a library from an attacker-controlled directory rather than a trusted one (CWE-426). An attacker triggers the flaw by convincing a user to open a crafted document or file in a location the attacker controls, such as a network share or web-accessible folder, causing a malicious DLL placed alongside the file to be loaded. Successful exploitation yields remote code execution with the privileges of the logged-on user, potentially giving attackers a foothold for follow-on activity such as malware or ransomware deployment. Any environment running Microsoft products that embed VBA is potentially affected, and typical exposure is broad because VBA ships with Microsoft Office deployments. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2026-04-13, indicating confirmed in-the-wild exploitation, with a 21% EPSS probability of exploitation in the next 30 days (97th percentile). Do: Apply Microsoft's mitigations per the CISA KEV required action and applicable BOD 22-01 guidance, prioritizing patching of Microsoft Office/VBA components in line with Microsoft's advisory for this vulnerability. As interim mitigation, prevent applications from loading libraries from untrusted, user-writable directories (e.g., avoid opening untrusted documents from network shares, web folders, or download locations) and ensure system-wide DLL search safety settings are enabled. Because there is no known public PoC and exploitation is confirmed in the wild, treat this as a high-priority remediation item and check patch-management and vulnerability-management records for coverage across Office/VBA-bearing endpoints. | — | 21% | KEV |
| masshundreds of millions of users potentially affected (VBA is embedded in Microsoft Office, which is deployed on the vast majority of enterprise and consumer… | |
| CVE-2020-9715 | Use-After-Free Code Execution Flaw in Adobe Acrobat Adobe Acrobat contains a use-after-free memory-corruption flaw (CWE-416) that can lead to arbitrary code execution. The condition is triggered when the application processes specially crafted PDF content, freeing memory that is later reused, typically when a user opens a malicious PDF file. A successful exploit lets an attacker run code in the context of the current user, potentially enabling malware installation or further compromise of the workstation. Any environment running an unpatched version of Adobe Acrobat is affected, particularly fleets still on legacy or unmanaged builds. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2026-04-13, confirming exploitation in the wild; its 48.6% EPSS score (99th percentile) signals a high likelihood of near-term exploitation, while no public proof-of-concept is known and ransomware association is unconfirmed. Do: Update Adobe Acrobat to the latest release available from Adobe; the fix shipped in Adobe's 2020 security updates, so any installation not updated since then remains vulnerable. Because the flaw is now in the CISA KEV catalog, inventory installed Acrobat versions across the estate and treat unpatched hosts as actively targeted, following BOD 22-01 guidance for federal systems. As an interim mitigation, restrict opening of untrusted PDFs and use Acrobat's protected/preview mode until patching is complete. | 7.8 | 49% | KEV PoC |
| masshundreds of millions of desktop installations worldwide (dominant PDF-viewer installed base) | |
| CVE-2023-21529 | Authenticated Deserialization RCE in Microsoft Exchange Server (CVE-2023-21529) CVE-2023-21529 is a deserialization-of-untrusted-data flaw (CWE-502) in on-premises Microsoft Exchange Server that allows remote code execution. Per its CVSS vector, an attacker with valid low-privileged credentials (PR:L) sends crafted untrusted serialized data to the server over the network, requiring no user interaction. Successful exploitation yields code execution on the Exchange server, exposing mail stores and providing a foothold for lateral movement, and related coverage ties it to the fast-moving Storm-1175 ransomware operation, with ransomware use listed as known in CISA's KEV entry. Organizations running self-hosted Exchange Server are in scope; the source data does not list specific affected builds, but the fix shipped in Microsoft's February 2023 Patch Tuesday updates. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-13, EPSS estimates a 62.1% probability of exploitation within 30 days (99th percentile), and no public proof-of-concept is known. Do: Apply the February 2023 Exchange Server security updates to every on-premises Exchange server; U.S. federal agencies must mitigate or patch per BOD 22-01 following the KEV listing. Because exploitation requires authenticated low-privilege access, inventory exposed OWA/ECP endpoints, review and rotate credentials, and hunt for compromise indicators (unusual processes, webshells, unexpected mailbox activity) given known ransomware use. | 8.8 | 62% | KEV ransomware |
| mass≈50,000–100,000 internet-exposed on-prem Exchange servers; on-prem Exchange plausibly hosts 1M+ users worldwide | |
| CVE-2023-36424 | Local Privilege Escalation via Out-of-Bounds Read in Windows CLFS Driver CVE-2023-36424 is an out-of-bounds read (CWE-125) in the Windows Common Log File System (CLFS) driver, a kernel component responsible for managing log files on Windows. A local attacker who can already execute limited-privilege code on an affected system can trigger the bug through crafted interaction with log file data, with no user interaction required. Successful exploitation yields elevation of privilege, giving the attacker high-privilege (typically SYSTEM-level) control of the host — a common post-exploitation step in broader intrusion and ransomware chains. All branches named in the advisory are affected — Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), and Windows Server 2008, 2012, 2016 and 2019 — making this effectively a fleet-wide Windows issue. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-13, confirming exploitation in the wild; EPSS puts the 30-day exploitation probability at 12.2% (96th percentile), while ransomware use is listed as unknown and no public proof-of-concept is known. Do: Apply Microsoft's security update for CVE-2023-36424 across all affected Windows 10/11 and Windows Server versions, prioritizing servers and admin workstations where a local SYSTEM-level escalation directly enables lateral movement, and use patch inventory to confirm the cumulative update containing the CLFS fix is installed on every host. Federal agencies must meet the BOD 22-01 remediation deadline (two weeks after the 2026-04-13 KEV addition). Because there is no public proof-of-concept and detections are limited, patching — rather than monitoring — is the primary mitigation. | 7.8 | 12% | KEV |
| mass≈1 billion+ installations (Windows 10/11 PCs and Windows Server hosts running the affected versions) | |
| CVE-2025-60710 | Link Following Privilege Escalation in Microsoft Windows Host Process for Tasks CVE-2025-60710 is a link-following flaw (CWE-59, improper link resolution before file access) in the Host Process for Windows Tasks on Microsoft Windows. A local attacker with limited (low-privilege) access can trigger the flaw by causing the host process to follow a manipulated link or junction/symlink during file access, redirecting its privileged file operations. Successful exploitation yields elevation of privilege on the local system, with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.8). Affected systems are Windows 11 24H2, Windows 11 25H2, and Windows Server 2025. The vulnerability is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-13 with known ransomware use, and EPSS estimates a 4.6% chance of exploitation in the next 30 days (91st percentile). Do: Apply Microsoft's current security updates for Windows 11 24H2, Windows 11 25H2, and Windows Server 2025 as soon as possible, prioritizing servers and workstations accessible to ransomware operators; the local attack vector means any compromised low-privileged account or endpoint is sufficient. Federal agencies and BOD 22-01-covered organizations must remediate or apply vendor mitigations per the KEV required action within the standard KEV timeline. Inventory systems still running unpatched 24H2/25H2 and Server 2025 builds, and monitor for post-compromise local privilege escalation activity as part of ransomware incident response. | 7.8 | 5% | KEV ransomware |
| masshundreds of millions of endpoints (Windows 11 24H2/25H2 workstations plus Windows Server 2025 deployments) | |
| CVE-2026-21643 | Unauthenticated SQL Injection to Code Execution in Fortinet FortiClient EMS 7.4.4 CVE-2026-21643 is a critical SQL injection flaw (CWE-89, improper neutralization of special elements used in an SQL command) in Fortinet FortiClient EMS 7.4.4, scored 9.8 critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An unauthenticated remote attacker can trigger it by sending specifically crafted HTTP requests to the EMS server, and successful injection allows execution of unauthorized code or commands, yielding high confidentiality, integrity, and availability impact. Any organization running the affected FortiClient EMS release is exposed, with internet-facing EMS management servers at greatest risk. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-04-13, EPSS assigns a 94.1% probability of exploitation within 30 days (99.9th-plus percentile), and news reports describe active zero-day exploitation that prompted Fortinet to issue emergency patches, alongside related FortiClient EMS hotfixes (CVE-2026-35616). Do: Upgrade affected FortiClient EMS 7.4.4 deployments using the emergency patch/hotfix Fortinet has released (see the Fortinet PSIRT advisory for fixed builds), prioritizing internet-exposed EMS servers; federal agencies must satisfy the BOD 22-01 requirement per the KEV listing. Until patched, restrict public exposure of the EMS web interface and review web access and database logs for signs of crafted HTTP requests or unexpected command execution. | 9.8 | 94% | KEV PoC |
| largeon the order of tens of thousands of FortiClient EMS server deployments (estimate) |
Full article349 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananApr 14, 2026Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added half a dozen security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The list of vulnerabilities is as follows -
- CVE-2026-21643 (CVSS score: 9.1) - An SQL injection vulnerability in Fortinet FortiClient EMS that could allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
- CVE-2020-9715 (CVSS score: 7.8) - A use-after-free vulnerability in Adobe Acrobat Reader that could result in remote code execution.
- CVE-2023-36424 (CVSS score: 7.8) - An out-of-bounds read vulnerability in Microsoft Windows Common Log File System Driver that could result in privilege escalation.
- CVE-2023-21529 (CVSS score: 8.8) - A deserialization of untrusted data in Microsoft Exchange Server that could allow an authenticated attacker to achieve remote code execution.
- CVE-2025-60710 (CVSS score: 7.8) - An improper link resolution before file access vulnerability in Host Process for Windows Tasks that could allow an authorized attacker to elevate privileges locally.
- CVE-2012-1854 (CVSS score: 7.8) - An insecure library loading vulnerability in Microsoft Visual Basic for Applications (VBA) that could result in remote code execution.
The addition of CVE-2026-21643 to the KEV catalog comes after Defused Cyber said it detected exploitation attempts targeting the flaw since March 24, 2026. Last week, Microsoft revealed that a threat actor it tracks as Storm-1175 has been weaponizing CVE-2023-21529 in attacks to deliver Medusa ransomware.
As for CVE-2012-1854, the Windows makeracknowledged in an advisory released in July 2012 that it's aware of "limited, targeted attacks" attempting to abuse the vulnerability. The exact nature of the attacks is presently unknown.
There are currently no public reports referencing the exploitation of the remaining three vulnerabilities. In light of active attacks, Federal Civilian Executive Branch (FCEB) agencies are required to apply the fixes by April 27, 2026. Patches for the FortiClient EMS vulnerability should be implemented by April 16, 2026.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/04/cisa-adds-6-known-exploited-flaws-in.html