INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Adobe, Fortinet, Microsoft Exchange Server Exploit Vulnerabilities Catalog

| 2026-04-14 07:38 CRITICAL HIGH
Executive Summary AI-generated
The US agency has added a slew of critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, with the most recent additions including CVE-2026-21643 and CVE-2012-1854. These flaws, which were discovered in Adobe Acrobat Reader, Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability, Fortinet SQL Injection Vulnerability, and Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability among others, pose a significant threat to the security of federal agencies' networks. The agency has ordered affected systems to be patched by April 27, 2026, except for CVE-2026-21643 which must be addressed by April 16, 2026. This highlights the urgent need for timely and effective remediation efforts to prevent potential exploitation and minimize the risk of catastrophic consequences.
Technical Mitigations AI-generated
* Implement secure coding practices, such as input validation and sanitization, to prevent Prototype Pollution Vulnerability (CVE-2026-34621) attacks. * Regularly update and patch Microsoft Exchange Server and Windows systems to address Out-of-Bounds Read Vulnerabilities (CVE-2023-36424) and privilege escalation risks (CVE-2023-21529). * Use secure protocols, such as HTTPS, when transmitting sensitive data over the internet to prevent SQL Injection vulnerabilities in Fortinet FortiClient EMS (CVE-2026-21643). * Implement proper error handling and logging mechanisms to detect and respond to use-after-free vulnerabilities in Adobe Acrobat Reader (CVE-2020-9715) and Microsoft Exchange Server.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2020-9715CVE-2020-9715 CVE-2023-36424CVE-2023-36424 CVE-2023-21529CVE-2023-21529 CVE-2026-34621CVE-2026-34621 CVE-2025-60710CVE-2025-60710 CVE-2026-21643CVE-2026-21643 CVE-2012-1854CVE-2012-1854
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎July 2012
Threat actors used a known exploit of CVE-2012-1854 in Windows to target the vulnerability.
infrastructure Windows
vulnerability CVE-2012-1854
‎March 24, 2026
Threat actors used a known exploit of CVE-2026-21643 to target Microsoft Exchange Server.
vulnerability CVE-2026-21643
organisation KEV
‎2026/04/07
Threat actors used a vulnerability in Adobe Acrobat Reader to target Microsoft Exchange Server and exploit Medusa ransomware.
vulnerability CVE-2026-21643
infrastructure Windows
tactic T1584.004 - Server
vulnerability CVE-2026-34621
vulnerability CVE-2012-1854
vulnerability CVE-2020-9715
vulnerability CVE-2023-21529
vulnerability CVE-2023-36424
vulnerability CVE-2025-60710
vulnerability CVSS score of 8.6
infrastructure 8.6
organisation Reader Prototype Pollution Vulnerability
organisation Microsoft
tactic T1059.005 - Visual Basic
organisation Microsoft Exchange
organisation Untrusted Data Vulnerability
organisation Adobe
infrastructure 21529 Server Deserialization
tactic Ransomware
organisation Storm-1175
‎Apr 14, 2026
Threat actors exploited known vulnerabilities in Adobe, Fortinet, Microsoft Exchange Server and Windows to gain unauthorized access.
‎2026/04/14
The US Cybersecurity and Infrastructure Security Agency (CISA) added vulnerabilities to the Known Exploited Vulnerabilities catalog.
organisation SQL
organisation Fortinet FortiClient EMS
infrastructure Windows
organisation Microsoft
organisation Host Process for Windows Tasks
organisation Microsoft Exchange
organisation CVE-2020-9715
organisation CVE-2023-21529
organisation CVE-2023-36424
organisation CVE-2025-60710
organisation VBA
organisation an SQL Command
‎April 16, 2026
Threat actors used a known exploit of CVE-2026-21643 in Adobe products to target Microsoft Exchange Server and Microsoft Windows systems.
vulnerability CVE-2026-21643
‎April 27, 2026
The U.S. CISA directive orders federal agencies to fix vulnerabilities in Adobe, Fortinet, Microsoft Exchange Server and Windows by April 27, 2026, except for CVE-2026-21643 which must be addressed by April 16, 2026.
vulnerability CVE-2026-21643
‎April 27, 2026
Threat actors exploited known vulnerabilities in Adobe, Fortinet, Microsoft Exchange Server and Windows to gain unauthorized access.
‎April 27
Threat actors used a known exploit to target Adobe, Fortinet and Microsoft Exchange Server vulnerabilities.
attribution FCEB
attribution Federal Civilian Executive Branch
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎8.6
Software Version
Metrics
infrastructure
21,529
Server Deserialization
Metrics
infrastructure
‎Microsoft Office
Affected Product