CISA Adds Seven Known Exploited Vulnerabilities to Catalog

2026-04-13T19:24:10Z31c9bd167cc59bcdd8d38bea6ed157874b356ab34836b214581316d5995fa129
AdobeBOD 22-01CISACitrixF5FortinetGoogleIvantiKEVKnown Exploited VulnerabilitiesMicrosoftRCESQL injectionTrueConfactive exploitationcode injectiondeserializationimproper access controlout-of-bounds readpatchingprototype pollutionuse-after-freevulnerability management

What happened

CISA added 13 vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog in early April 2026 (per multiple alerts), based on evidence of active exploitation. The additions affect multiple vendors and products (Microsoft, Adobe, Fortinet, Ivanti, Citrix, F5, Google, TrueConf, etc.) and include high-impact issues such as remote code execution, SQL injection, deserialization of untrusted data, use-after-free, prototype pollution, out-of-bounds reads, code-injection, and improper access control. CISA reiterates BOD 22-01 remediation requirements and urges timely patching and mitigation.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
31c9bd167cc59bcdd8d38bea6ed157874b356ab34836b214581316d5995fa129
Enrichment time
2026-04-13T19:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.