logo

CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software

ID: 4f0e8ca4-8c41-5e6d-ad73-ea9f67f3800b

STIX ID: report--4f0e8ca4-8c41-5e6d-ad73-ea9f67f3800b

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-04-14

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

CISA added six high-severity vulnerabilities to its Known Exploited Vulnerabilities catalog because of evidence of active exploitation. Notable entries include CVE-2026-21643 (Fortinet FortiClient EMS SQL injection, CVSS 9.1) with exploitation attempts observed since March 24, 2026, and CVE-2023-21529 (Microsoft Exchange deserialization, CVSS 8.8) which Microsoft links to actor Storm-1175 delivering Medusa ransomware; FCEB agencies are required to remediate by April 27, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.