# CISA Adds Seven Known Exploited Vulnerabilities to KEV Catalog: Federal Agencies Face Urgent Remediation Deadlines


The Cybersecurity and Infrastructure Security Agency (CISA) has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following confirmed evidence of active exploitation in the wild. The additions span Microsoft, Adobe, and Fortinet products—critical infrastructure relied upon by federal agencies and enterprises worldwide. These vulnerabilities represent a significant escalation in threat landscape and demand immediate attention from organizations across all sectors.


## The Threat


CISA's KEV Catalog serves as a living, curated list of Common Vulnerabilities and Exposures (CVEs) for which real-world exploitation has been documented. Unlike theoretical vulnerabilities, KEV entries signal active, weaponized threats—meaning malicious cyber actors have already developed working exploits and are using them in the field. The addition of these seven vulnerabilities underscores a critical reality: threat actors are not waiting for patches or moving at the pace of organizational remediation timelines.


The newly cataloged vulnerabilities span multiple attack vectors: library loading flaws in legacy VBA implementations, memory corruption bugs in document processors, and authentication bypass weaknesses in enterprise infrastructure. What ties them together is exploitation evidence. These are not future threats or hypothetical attack scenarios—these are active problems requiring immediate action.


CISA's action is driven by Binding Operational Directive (BOD) 22-01: *Reducing the Significant Risk of Known Exploited Vulnerabilities*. Issued in 2022, BOD 22-01 established the KEV Catalog as the authoritative source for identifying vulnerabilities that pose significant risk to federal civilian networks. The directive requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by CISA-assigned due dates—failure to comply can trigger federal enforcement action.


However, the scope of concern extends well beyond government. CISA has issued a strong recommendation that all organizations—private sector, state and local government, critical infrastructure operators, and enterprises of all sizes—prioritize remediation of KEV Catalog entries as core vulnerability management practice. For many organizations running Microsoft, Adobe, and Fortinet products, this means urgent action is required.


## Severity and Impact


| CVE | Product | Vulnerability Type | Active Exploitation | FCEB Remediation Required |

|-----|---------|-------------------|---------------------|----|

| CVE-2012-1854 | Microsoft VBA | Insecure Library Loading | Yes | Yes |

| CVE-2020-9715 | Adobe Acrobat | Use-After-Free | Yes | Yes |

| CVE-2023-21529 | Microsoft Exchange Server | Deserialization of Untrusted Data | Yes | Yes |

| CVE-2023-36424 | Microsoft Windows | Out-of-Bounds Read | Yes | Yes |

| CVE-2025-60710 | Microsoft Windows | Link Following | Yes | Yes |

| CVE-2026-21643 | Fortinet Products | SQL Injection | Yes | Yes |

| CVE-2026-34621 | Adobe Acrobat & Reader | Prototype Pollution | Yes | Yes |


*Note: Complete CVSS scoring, attack vector details, and technical severity metrics are available in the National Vulnerability Database (NVD) and respective vendor advisories linked below.*


The threat landscape reflected in this update is concerning. Microsoft vulnerabilities dominate the list—four of seven entries affect Microsoft products spanning VBA, Windows, and Exchange Server. Adobe has two new entries covering both Acrobat and Reader. Fortinet's inclusion signals that even network infrastructure is being actively exploited through SQL injection weaknesses. The breadth of affected software categories means that most enterprise networks will have at least some exposure.


## Affected Products


Microsoft:

  • Visual Basic for Applications (VBA) - Legacy installations and Office versions using VBA
  • Windows - Multiple versions affected by CVE-2023-36424 and CVE-2025-60710
  • Exchange Server - All supported versions vulnerable to CVE-2023-21529

  • Adobe:

  • Acrobat (all supported versions)
  • Reader (all supported versions)

  • Fortinet:

  • FortiGate firewalls
  • Related Fortinet security appliances with SQL backend interfaces

  • Organizations using any combination of these products should assume exposure until patches are deployed and verified.


    ## Mitigations


    Immediate Actions (Within 48 Hours):

  • Audit your environment for installed Microsoft Office, Windows, Exchange Server, Adobe products, and Fortinet appliances
  • Check current patch levels against vendor security bulletins
  • For FCEB agencies: document the due date assigned by CISA for each vulnerability and create remediation tickets with executive accountability

  • Short-Term Remediation (1-2 Weeks):

  • Prioritize Exchange Server updates (CVE-2023-21529) given the critical nature of email infrastructure
  • Deploy Windows security updates for CVE-2023-36424 and CVE-2025-60710 through standard patch management
  • Update Adobe Acrobat and Reader across your organization
  • Patch Fortinet appliances to latest firmware versions addressing CVE-2026-21643
  • For legacy VBA (CVE-2012-1854): assess business need; if still in use, isolate affected systems or restrict macro execution via Group Policy

  • Compensating Controls (While Patching):

  • Disable macros by default in Office unless explicitly required
  • Restrict Exchange Server network access to trusted networks only
  • Implement network segmentation to limit lateral movement from compromised Windows systems
  • Deploy application whitelisting on critical systems to prevent exploitation of unpatched vulnerabilities
  • Monitor firewall and proxy logs for suspicious SQL queries targeting Fortinet appliances
  • Apply the principle of least privilege to all service accounts

  • Long-Term Actions:

  • Subscribe to CISA's KEV Catalog RSS feed or automated notifications to track new additions
  • Integrate KEV Catalog tracking into your vulnerability management platform
  • Establish SLA targets for patching KEV vulnerabilities (ideally 30 days or sooner depending on risk tolerance)
  • Conduct threat hunting for indicators of compromise related to these CVEs

  • ## References


  • CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities
  • Binding Operational Directive 22-01: https://www.cisa.gov/bod-22-01
  • BOD 22-01 Fact Sheet: https://www.cisa.gov/sites/default/files/publications/bod-22-01-fact-sheet.pdf
  • National Vulnerability Database (NVD): https://nvd.nist.gov
  • Microsoft Security Updates: https://msrc.microsoft.com
  • Adobe Security Updates: https://helpx.adobe.com/security.html
  • Fortinet Security Advisories: https://www.fortinet.com/products/threat-prevention/threat-research

  • ---


    The Bottom Line: CISA's addition of these seven vulnerabilities to the KEV Catalog is a clear warning that active exploitation is underway. For federal agencies, remediation is mandatory with assigned deadlines. For everyone else, these entries should trigger urgent action within your vulnerability management program. The combination of Microsoft, Adobe, and Fortinet products in this batch means most enterprises cannot afford to delay—the attack surface is simply too broad, and the evidence of weaponization too clear.