CISA's list that day
13 April 2026
On CISA added 7 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Visual Basic for Applications (VBA), Adobe Acrobat, Microsoft Exchange Server and 3 other products. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2023-21529Deserialization of Untrusted Data | Microsoft Exchange Server | Patch nowRansomware use, listed within a year | 0.59 | ||
| CVE-2025-60710Link Following | Microsoft Windows | Patch nowRansomware use, listed within a year | 0.05 | ||
| CVE-2026-21643SQL Injection | Fortinet FortiClient EMS | Patch this weekEPSS 0.94 | 0.94 | ||
| CVE-2020-9715Use-After-Free | Adobe Acrobat | Patch soon | 0.49 | ||
| CVE-2012-1854Visual Basic for Applications Insecure Library Loading | Microsoft Visual Basic for Applications (VBA) | Patch soon | 0.21 | ||
| CVE-2023-36424Out-of-Bounds Read | Microsoft Windows | Patch soon | 0.12 | ||
| CVE-2026-34621Prototype Pollution | Adobe Acrobat and Reader | Patch soon | 0.02 |