CISA Adds Seven Known Exploited Vulnerabilities to Catalog
2026-04-13T19:24:10Z•31c9bd167cc59bcdd8d38bea6ed157874b356ab34836b214581316d5995fa129
AdobeBOD 22-01CISACitrixF5FortinetGoogleIvantiKEVKnown Exploited VulnerabilitiesMicrosoftRCESQL injectionTrueConfactive exploitationcode injectiondeserializationimproper access controlout-of-bounds readpatchingprototype pollutionuse-after-freevulnerability management
What happened
CISA added 13 vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog in early April 2026 (per multiple alerts), based on evidence of active exploitation. The additions affect multiple vendors and products (Microsoft, Adobe, Fortinet, Ivanti, Citrix, F5, Google, TrueConf, etc.) and include high-impact issues such as remote code execution, SQL injection, deserialization of untrusted data, use-after-free, prototype pollution, out-of-bounds reads, code-injection, and improper access control. CISA reiterates BOD 22-01 remediation requirements and urges timely patching and mitigation.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 31c9bd167cc59bcdd8d38bea6ed157874b356ab34836b214581316d5995fa129
- Enrichment time
- 2026-04-13T19:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.