# CISA Adds Seven Known Exploited Vulnerabilities to KEV Catalog: Federal Agencies Face Urgent Remediation Deadlines
The Cybersecurity and Infrastructure Security Agency (CISA) has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following confirmed evidence of active exploitation in the wild. The additions span Microsoft, Adobe, and Fortinet products—critical infrastructure relied upon by federal agencies and enterprises worldwide. These vulnerabilities represent a significant escalation in threat landscape and demand immediate attention from organizations across all sectors.
## The Threat
CISA's KEV Catalog serves as a living, curated list of Common Vulnerabilities and Exposures (CVEs) for which real-world exploitation has been documented. Unlike theoretical vulnerabilities, KEV entries signal active, weaponized threats—meaning malicious cyber actors have already developed working exploits and are using them in the field. The addition of these seven vulnerabilities underscores a critical reality: threat actors are not waiting for patches or moving at the pace of organizational remediation timelines.
The newly cataloged vulnerabilities span multiple attack vectors: library loading flaws in legacy VBA implementations, memory corruption bugs in document processors, and authentication bypass weaknesses in enterprise infrastructure. What ties them together is exploitation evidence. These are not future threats or hypothetical attack scenarios—these are active problems requiring immediate action.
CISA's action is driven by Binding Operational Directive (BOD) 22-01: *Reducing the Significant Risk of Known Exploited Vulnerabilities*. Issued in 2022, BOD 22-01 established the KEV Catalog as the authoritative source for identifying vulnerabilities that pose significant risk to federal civilian networks. The directive requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by CISA-assigned due dates—failure to comply can trigger federal enforcement action.
However, the scope of concern extends well beyond government. CISA has issued a strong recommendation that all organizations—private sector, state and local government, critical infrastructure operators, and enterprises of all sizes—prioritize remediation of KEV Catalog entries as core vulnerability management practice. For many organizations running Microsoft, Adobe, and Fortinet products, this means urgent action is required.
## Severity and Impact
| CVE | Product | Vulnerability Type | Active Exploitation | FCEB Remediation Required |
|-----|---------|-------------------|---------------------|----|
| CVE-2012-1854 | Microsoft VBA | Insecure Library Loading | Yes | Yes |
| CVE-2020-9715 | Adobe Acrobat | Use-After-Free | Yes | Yes |
| CVE-2023-21529 | Microsoft Exchange Server | Deserialization of Untrusted Data | Yes | Yes |
| CVE-2023-36424 | Microsoft Windows | Out-of-Bounds Read | Yes | Yes |
| CVE-2025-60710 | Microsoft Windows | Link Following | Yes | Yes |
| CVE-2026-21643 | Fortinet Products | SQL Injection | Yes | Yes |
| CVE-2026-34621 | Adobe Acrobat & Reader | Prototype Pollution | Yes | Yes |
*Note: Complete CVSS scoring, attack vector details, and technical severity metrics are available in the National Vulnerability Database (NVD) and respective vendor advisories linked below.*
The threat landscape reflected in this update is concerning. Microsoft vulnerabilities dominate the list—four of seven entries affect Microsoft products spanning VBA, Windows, and Exchange Server. Adobe has two new entries covering both Acrobat and Reader. Fortinet's inclusion signals that even network infrastructure is being actively exploited through SQL injection weaknesses. The breadth of affected software categories means that most enterprise networks will have at least some exposure.
## Affected Products
Microsoft:
Adobe:
Fortinet:
Organizations using any combination of these products should assume exposure until patches are deployed and verified.
## Mitigations
Immediate Actions (Within 48 Hours):
Short-Term Remediation (1-2 Weeks):
Compensating Controls (While Patching):
Long-Term Actions:
## References
---
The Bottom Line: CISA's addition of these seven vulnerabilities to the KEV Catalog is a clear warning that active exploitation is underway. For federal agencies, remediation is mandatory with assigned deadlines. For everyone else, these entries should trigger urgent action within your vulnerability management program. The combination of Microsoft, Adobe, and Fortinet products in this batch means most enterprises cannot afford to delay—the attack surface is simply too broad, and the evidence of weaponization too clear.