CISA adds seven known exploited vulnerabilities to catalog
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation:
CVE-2012-1854 Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability, CVE-2020-9715 Adobe Acrobat Use-After-Free Vulnerability, CVE-2023-21529 Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability, CVE-2023-36424 Microsoft Windows Out-of-Bounds Read Vulnerability, CVE-2025-60710 Microsoft Windows Link Following Vulnerability, CVE-2026-21643 Fortinet SQL Injection Vulnerability, CVE-2026-34621 Adobe Acrobat and Reader Prototype Pollution Vulnerability.
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.