ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Adobe, Fortinet, Microsoft Windows, Microsoft Exchange Server flaws to its Known Exploited Vulnerabilities catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2012-1854
Insecure Library Loading (CWE-426) in Microsoft Visual Basic for Applications

Microsoft Visual Basic for Applications (VBA) fails to fully specify the search path used when loading dynamic-link libraries, so applications embedding VBA may load a library from an attacker-controlled directory rather than a trusted one (CWE-426). An attacker triggers the flaw by convincing a user to open a crafted document or file in a location the attacker controls, such as a network share or web-accessible folder, causing a malicious DLL placed alongside the file to be loaded. Successful exploitation yields remote code execution with the privileges of the logged-on user, potentially giving attackers a foothold for follow-on activity such as malware or ransomware deployment. Any environment running Microsoft products that embed VBA is potentially affected, and typical exposure is broad because VBA ships with Microsoft Office deployments. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2026-04-13, indicating confirmed in-the-wild exploitation, with a 21% EPSS probability of exploitation in the next 30 days (97th percentile).

Do: Apply Microsoft's mitigations per the CISA KEV required action and applicable BOD 22-01 guidance, prioritizing patching of Microsoft Office/VBA components in line with Microsoft's advisory for this vulnerability. As interim mitigation, prevent applications from loading libraries from untrusted, user-writable directories (e.g., avoid opening untrusted documents from network shares, web folders, or download locations) and ensure system-wide DLL search safety settings are enabled. Because there is no known public PoC and exploitation is confirmed in the wild, treat this as a high-priority remediation item and check patch-management and vulnerability-management records for coverage across Office/VBA-bearing endpoints.

21% KEV
  • Microsoft Visual Basic for Applications (VBA)
masshundreds of millions of users potentially affected (VBA is embedded in Microsoft Office, which is deployed on the vast majority of enterprise and consumer…
CVE-2020-9715
Use-After-Free Code Execution Flaw in Adobe Acrobat

Adobe Acrobat contains a use-after-free memory-corruption flaw (CWE-416) that can lead to arbitrary code execution. The condition is triggered when the application processes specially crafted PDF content, freeing memory that is later reused, typically when a user opens a malicious PDF file. A successful exploit lets an attacker run code in the context of the current user, potentially enabling malware installation or further compromise of the workstation. Any environment running an unpatched version of Adobe Acrobat is affected, particularly fleets still on legacy or unmanaged builds. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2026-04-13, confirming exploitation in the wild; its 48.6% EPSS score (99th percentile) signals a high likelihood of near-term exploitation, while no public proof-of-concept is known and ransomware association is unconfirmed.

Do: Update Adobe Acrobat to the latest release available from Adobe; the fix shipped in Adobe's 2020 security updates, so any installation not updated since then remains vulnerable. Because the flaw is now in the CISA KEV catalog, inventory installed Acrobat versions across the estate and treat unpatched hosts as actively targeted, following BOD 22-01 guidance for federal systems. As an interim mitigation, restrict opening of untrusted PDFs and use Acrobat's protected/preview mode until patching is complete.

7.849% KEV PoC
  • Adobe Acrobat
masshundreds of millions of desktop installations worldwide (dominant PDF-viewer installed base)
CVE-2023-21529
Authenticated Deserialization RCE in Microsoft Exchange Server (CVE-2023-21529)

CVE-2023-21529 is a deserialization-of-untrusted-data flaw (CWE-502) in on-premises Microsoft Exchange Server that allows remote code execution. Per its CVSS vector, an attacker with valid low-privileged credentials (PR:L) sends crafted untrusted serialized data to the server over the network, requiring no user interaction. Successful exploitation yields code execution on the Exchange server, exposing mail stores and providing a foothold for lateral movement, and related coverage ties it to the fast-moving Storm-1175 ransomware operation, with ransomware use listed as known in CISA's KEV entry. Organizations running self-hosted Exchange Server are in scope; the source data does not list specific affected builds, but the fix shipped in Microsoft's February 2023 Patch Tuesday updates. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-13, EPSS estimates a 62.1% probability of exploitation within 30 days (99th percentile), and no public proof-of-concept is known.

Do: Apply the February 2023 Exchange Server security updates to every on-premises Exchange server; U.S. federal agencies must mitigate or patch per BOD 22-01 following the KEV listing. Because exploitation requires authenticated low-privilege access, inventory exposed OWA/ECP endpoints, review and rotate credentials, and hunt for compromise indicators (unusual processes, webshells, unexpected mailbox activity) given known ransomware use.

8.862% KEV ransomware
  • Microsoft Exchange Server
mass≈50,000–100,000 internet-exposed on-prem Exchange servers; on-prem Exchange plausibly hosts 1M+ users worldwide
CVE-2023-36424
Local Privilege Escalation via Out-of-Bounds Read in Windows CLFS Driver

CVE-2023-36424 is an out-of-bounds read (CWE-125) in the Windows Common Log File System (CLFS) driver, a kernel component responsible for managing log files on Windows. A local attacker who can already execute limited-privilege code on an affected system can trigger the bug through crafted interaction with log file data, with no user interaction required. Successful exploitation yields elevation of privilege, giving the attacker high-privilege (typically SYSTEM-level) control of the host — a common post-exploitation step in broader intrusion and ransomware chains. All branches named in the advisory are affected — Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), and Windows Server 2008, 2012, 2016 and 2019 — making this effectively a fleet-wide Windows issue. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-13, confirming exploitation in the wild; EPSS puts the 30-day exploitation probability at 12.2% (96th percentile), while ransomware use is listed as unknown and no public proof-of-concept is known.

Do: Apply Microsoft's security update for CVE-2023-36424 across all affected Windows 10/11 and Windows Server versions, prioritizing servers and admin workstations where a local SYSTEM-level escalation directly enables lateral movement, and use patch inventory to confirm the cumulative update containing the CLFS fix is installed on every host. Federal agencies must meet the BOD 22-01 remediation deadline (two weeks after the 2026-04-13 KEV addition). Because there is no public proof-of-concept and detections are limited, patching — rather than monitoring — is the primary mitigation.

7.812% KEV
  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2, 23H2
  • Microsoft Windows Server 2008, 2012, 2016, 2019
mass≈1 billion+ installations (Windows 10/11 PCs and Windows Server hosts running the affected versions)
CVE-2025-60710
Link Following Privilege Escalation in Microsoft Windows Host Process for Tasks

CVE-2025-60710 is a link-following flaw (CWE-59, improper link resolution before file access) in the Host Process for Windows Tasks on Microsoft Windows. A local attacker with limited (low-privilege) access can trigger the flaw by causing the host process to follow a manipulated link or junction/symlink during file access, redirecting its privileged file operations. Successful exploitation yields elevation of privilege on the local system, with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.8). Affected systems are Windows 11 24H2, Windows 11 25H2, and Windows Server 2025. The vulnerability is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-13 with known ransomware use, and EPSS estimates a 4.6% chance of exploitation in the next 30 days (91st percentile).

Do: Apply Microsoft's current security updates for Windows 11 24H2, Windows 11 25H2, and Windows Server 2025 as soon as possible, prioritizing servers and workstations accessible to ransomware operators; the local attack vector means any compromised low-privileged account or endpoint is sufficient. Federal agencies and BOD 22-01-covered organizations must remediate or apply vendor mitigations per the KEV required action within the standard KEV timeline. Inventory systems still running unpatched 24H2/25H2 and Server 2025 builds, and monitor for post-compromise local privilege escalation activity as part of ransomware incident response.

7.85% KEV ransomware
  • microsoft Windows 11 24H2 24H2 (all builds prior to the vendor security update; no specific version range provided in source data)
  • microsoft Windows 11 25H2 25H2 (all builds prior to the vendor security update; no specific version range provided in source data)
  • microsoft Windows Server 2025 2025 (all builds prior to the vendor security update; no specific version range provided in source data)
masshundreds of millions of endpoints (Windows 11 24H2/25H2 workstations plus Windows Server 2025 deployments)
CVE-2026-21643
Unauthenticated SQL Injection to Code Execution in Fortinet FortiClient EMS 7.4.4

CVE-2026-21643 is a critical SQL injection flaw (CWE-89, improper neutralization of special elements used in an SQL command) in Fortinet FortiClient EMS 7.4.4, scored 9.8 critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An unauthenticated remote attacker can trigger it by sending specifically crafted HTTP requests to the EMS server, and successful injection allows execution of unauthorized code or commands, yielding high confidentiality, integrity, and availability impact. Any organization running the affected FortiClient EMS release is exposed, with internet-facing EMS management servers at greatest risk. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-04-13, EPSS assigns a 94.1% probability of exploitation within 30 days (99.9th-plus percentile), and news reports describe active zero-day exploitation that prompted Fortinet to issue emergency patches, alongside related FortiClient EMS hotfixes (CVE-2026-35616).

Do: Upgrade affected FortiClient EMS 7.4.4 deployments using the emergency patch/hotfix Fortinet has released (see the Fortinet PSIRT advisory for fixed builds), prioritizing internet-exposed EMS servers; federal agencies must satisfy the BOD 22-01 requirement per the KEV listing. Until patched, restrict public exposure of the EMS web interface and review web access and database logs for signs of crafted HTTP requests or unexpected command execution.

9.894% KEV PoC
  • Fortinet FortiClient EMS 7.4.4 (version listed by CISA; fixed builds per the Fortinet PSIRT advisory/emergency patch)
largeon the order of tens of thousands of FortiClient EMS server deployments (estimate)
CVE-2026-34621
Actively Exploited Prototype Pollution RCE in Adobe Acrobat and Reader

Adobe Acrobat and Acrobat Reader are affected by a prototype pollution vulnerability (CWE-1321) in which improperly controlled modification of object prototype attributes can lead to arbitrary code execution in the context of the current user. Attackers trigger the flaw by convincing a victim to open a malicious file, typically a crafted PDF, so user interaction is required. Successful exploitation yields code execution as the victim, with the CVSS scope-changed metric indicating impact that extends beyond the vulnerable component. Anyone running Acrobat or Reader versions 24.001.30356 or earlier or 26.001.21367 or earlier is affected. The flaw is being actively exploited in the wild — reportedly via malicious PDFs since December 2025 as a zero-day — and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-13 after fixes shipped in Adobe's April 2026 Patch Tuesday release; EPSS assigns a 7.1% probability of exploitation within 30 days (94th percentile).

Do: Upgrade Acrobat and Reader to a version later than 24.001.30356 (24.001 series) or 26.001.21367 (26.001 series) via Adobe's April 2026 security update, and audit installed versions across all endpoints. As a CISA KEV entry, US federal agencies must apply the vendor mitigations per BOD 22-01 guidance or discontinue use of the product if mitigations are unavailable. Until patched, treat PDFs from untrusted sources with caution and monitor for suspicious child-process activity spawned by Acrobat/Reader when files are opened.

8.67% KEV
  • Adobe Acrobat Reader (Acrobat Reader DC) 24.001.30356 and earlier; 26.001.21367 and earlier
  • Adobe Acrobat (Acrobat DC) 24.001.30356 and earlier; 26.001.21367 and earlier
masshundreds of millions of Acrobat/Reader installations worldwide, with likely millions still unpatched
Full article415 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe, Fortinet, Microsoft Exchange Server, and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the flaws added to the catalog:

  • CVE-2026-34621 Adobe Acrobat and Reader Prototype Pollution Vulnerability
  • CVE-2012-1854 Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability
  • CVE-2020-9715 Adobe Acrobat Use-After-Free Vulnerability
  • CVE-2023-21529 Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
  • CVE-2023-36424 Microsoft Windows Out-of-Bounds Read Vulnerability
  • CVE-2025-60710 Microsoft Windows Link Following Vulnerability
  • CVE-2026-21643 Fortinet SQL Injection Vulnerability

Last week, Adobe released emergency updates to address a critical vulnerability, tracked as CVE-2026-34621 (CVSS score of 8.6), in Adobe Acrobat Reader, which is being actively exploited. The flaw could allow attackers to execute malicious code on affected systems, making prompt patching essential to reduce the risk of compromise.

The vulnerability is an improperly controlled modification of object prototype attributes (‘Prototype Pollution’) that can lead to arbitrary code execution.

CISA also added to the KeV catalog the vulnerability CVE-2012-1854, which is an untrusted search path / DLL hijacking flaw affecting components of Microsoft Office VBA, specifically VBE6.dll used in Office and Visual Basic for Applications.

The third issue added to the catalog is the flaw CVE-2020-9715, which is a use-after-free issue that can lead to arbitrary code execution.        

The US agency also added CVE-2026-21643 flaw to the catalog. In February, Fortinet issued an urgent advisory to address a critical FortiClientEMS vulnerability, tracked as CVE-2026-21643 (CVSS score of 9.1).

The vulnerability is an improper neutralization of special elements used in an SQL Command (‘SQL Injection’) issue in FortiClientEMS. An unauthenticated attacker can trigger the flaw to execute unauthorized code or commands via specifically crafted HTTP requests.

A successful attack could give attackers an initial foothold in the target network, enabling lateral movement or malware deployment.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by April 27, 2026, except CVE-2026-21643, which must be addressed by April 16, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/190775/security/u-s-cisa-adds-adobe-fortinet-microsoft-windows-microsoft-exchange-server-and-microsoft-windows-flaws-to-its-known-exploited-vulnerabilities-catalog.html