# CISA KEV Update: Exchange Server, Adobe, MS Windows Exploits

> CISA adds seven vulnerabilities, including critical Microsoft Exchange Server deserialization, to its Known Exploited Vulnerabilities Catalog, urging immediate…

- Published: 2026-04-14T00:47:03.000Z
- Severity: critical
- Category: Vulnerabilities
- Tags: CVE-2012-1854, CVE-2020-9715, CVE-2023-21529, CVE-2023-36424, CVE-2025-60710, CVE-2026-21643, CVE-2026-34621, Microsoft Exchange Server, Adobe Acrobat, Microsoft Windows, Fortinet, CISA, KEV Catalog, Deserialization, Use After Free, SQL Injection
- Author: Runtime Rebel Intel
- Primary source: https://www.cisa.gov/news-events/alerts/2026/04/13/cisa-adds-seven-known-exploited-vulnerabilities-catalog
- Canonical: https://runtimerebel.com/blog/cisa-kev-update-exchange-server-adobe-ms-windows-exploits

## Key points

- Immediate impact: Organizations face active exploitation risks from seven vulnerabilities now in CISA's KEV Catalog.
- Affected systems: Microsoft Exchange, Adobe Acrobat, Fortinet, and various Microsoft Windows versions require urgent attention.
- Remediation: Prioritize patching all identified Known Exploited Vulnerabilities immediately to protect networks.

## CISA Adds Seven Known Exploited Vulnerabilities to KEV Catalog

The Cybersecurity and Infrastructure Security Agency (CISA) has updated its [Known Exploited Vulnerabilities (KEV) Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) by adding seven new vulnerabilities, confirming active exploitation of these flaws. This update underscores the persistent threat posed by previously identified security weaknesses that malicious actors continue to leverage. According to [CISA](https://www.cisa.gov/news-events/alerts/2026/04/13/cisa-adds-seven-known-exploited-vulnerabilities-catalog), these types of vulnerabilities are frequent attack vectors and present significant risks across all sectors, not just federal entities.

The KEV Catalog serves as a critical resource, established under [Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities](https://www.cisa.gov/binding-operational-directive-22-01). While BOD 22-01 mandates Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by specified due dates, CISA strongly advises all organizations to adopt similar rigorous patching strategies. The inclusion in this catalog signifies that a [CVE](/glossary#cve) is actively being exploited, making it an immediate threat that requires prioritised attention from security teams.

### Analysis of Notable Vulnerabilities and Their Impact

The seven vulnerabilities added span a range of products and attack types. Among them, several warrant immediate attention due to their potential impact and the severity of the underlying flaw. Here are the vulnerabilities added, along with their reported descriptions:

*   **[CVE-2012-1854](/cve/cve-2012-1854)**: Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability. Despite its age, this flaw continues to be a viable attack vector, highlighting the longevity of certain exploitation techniques.
*   **[CVE-2020-9715](/cve/cve-2020-9715)**: Adobe Acrobat Use-After-Free Vulnerability. This type of flaw can lead to [RCE](/glossary#rce) and is a common target for document-based attacks, often delivered via [Phishing](/glossary#phishing) campaigns.
*   **[CVE-2023-21529](/cve/cve-2023-21529)**: Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability. This vulnerability is particularly critical. Deserialization flaws in a widely deployed product like Microsoft Exchange Server can enable remote code execution, granting attackers significant control over compromised systems and access to sensitive communications. Organizations leveraging Microsoft Exchange Server versions vulnerable to this flaw must treat remediation as an absolute priority to prevent critical infrastructure compromise.
*   **[CVE-2023-36424](/cve/cve-2023-36424)**: Microsoft Windows Out-of-Bounds Read Vulnerability. Such vulnerabilities can lead to information disclosure or denial-of-service conditions, contributing to further exploitation chains.
*   **CVE-2025-60710**: Microsoft Windows Link Following Vulnerability.
*   **CVE-2026-21643**: Fortinet SQL Injection Vulnerability.
*   **CVE-2026-34621**: Adobe Acrobat and Reader Prototype Pollution Vulnerability.

It is notable that some of these CVEs (CVE-2025-60710, CVE-2026-21643, CVE-2026-34621) carry future-dated identifiers, suggesting that they may be pre-disclosed vulnerabilities or represent a forward-looking assessment by CISA of impending threats. While NVD entries and public [CVSS](/glossary#cvss) scores for these specific identifiers are not yet available, their inclusion in the KEV Catalog signifies CISA's intelligence on their active exploitation and the urgent need for organisations to prepare for their eventual public disclosure and patching.

### The Imperative for Timely Remediation

The inclusion of a vulnerability in CISA's KEV Catalog serves as a definitive signal that an organization's exposure to cyberattacks increases significantly if these flaws remain unaddressed. Active exploitation means attackers are already weaponizing these weaknesses, escalating the risk beyond theoretical concern to immediate operational threat. The older vulnerabilities on this list underscore that patch management is not a one-time task but an ongoing, iterative process requiring continuous vigilance.

## Actionable Recommendations: How to detect known exploited vulnerabilities and mitigate risks

Defenders must prioritize these KEV Catalog additions within their vulnerability management programs. Here's a breakdown of essential actions:

*   **Prioritize Patching**: The most direct and effective mitigation for all listed vulnerabilities is to apply vendor-provided patches without delay. This is particularly crucial for systems affected by the [Microsoft Exchange Server CVE-2023-21529 deserialization vulnerability mitigation](https://nvd.nist.gov/vuln/detail/CVE-2023-21529), given its potential for severe impact.
*   **Automated Patch Management**: Implement or enhance automated patching systems to ensure rapid deployment of security updates across the enterprise. Regularly audit these systems for effectiveness.
*   **Vulnerability Scanning and Assessment**: Conduct regular, comprehensive vulnerability scans to identify instances of these and other known exploited flaws within your network. Tools providing asset inventory and vulnerability mapping are essential.
*   **Network Segmentation and Least Privilege**: Adopt [Zero Trust](/glossary#zero-trust) principles, segmenting networks to limit the blast radius of any successful exploitation. Enforce least privilege for users and services to restrict [lateral movement](/glossary#lateral-movement) and [privilege escalation](/glossary#privilege-escalation) opportunities.
*   **Enhanced Monitoring**: Implement robust monitoring capabilities. Use [SIEM](/glossary#siem) and [EDR](/glossary#edr) solutions to monitor for [IoC](/glossary#ioc) associated with known exploitation attempts. Pay close attention to logs from affected systems, looking for unusual activity or unauthorized access attempts that could indicate a [C2](/glossary#c2) channel being established.
*   **Incident Response Planning**: Ensure your incident response plan is up-to-date and includes procedures for addressing actively exploited vulnerabilities. Conduct tabletop exercises to test response capabilities.
*   **Stay Informed**: Regularly consult the CISA KEV Catalog for updates. Subscribing to CISA's advisories ensures your organization remains informed of critical and actively exploited threats.

**Related:** [FortiClient EMS RCE via CVE-2023-48788 — Patch Guidance](/blog/forticlient-ems-rce-via-cve-2023-48788-patch-guidance), [CVE-2026-34621: Adobe Acrobat and Reader Zero-Day Emergency Patch](/blog/cve-2026-34621-adobe-acrobat-and-reader-zero-day-emergency-patch)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/cisa-kev-update-exchange-server-adobe-ms-windows-exploits
