CISA's list that day

13 April 2026

On CISA added 7 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Visual Basic for Applications (VBA), Adobe Acrobat, Microsoft Exchange Server and 3 other products. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2023-21529Deserialization of Untrusted DataMicrosoft Exchange ServerPatch nowRansomware use, listed within a year0.59
CVE-2025-60710Link FollowingMicrosoft WindowsPatch nowRansomware use, listed within a year0.05
CVE-2026-21643SQL InjectionFortinet FortiClient EMSPatch this weekEPSS 0.940.94
CVE-2020-9715Use-After-FreeAdobe AcrobatPatch soon0.49
CVE-2012-1854Visual Basic for Applications Insecure Library LoadingMicrosoft Visual Basic for Applications (VBA)Patch soon0.21
CVE-2023-36424Out-of-Bounds ReadMicrosoft WindowsPatch soon0.12
CVE-2026-34621Prototype PollutionAdobe Acrobat and ReaderPatch soon0.02