CISA Adds Six Actively Exploited Fortinet, Microsoft and Adobe Flaws to KEV

April 6, 2026 — CISA added six actively exploited vulnerabilities spanning Fortinet, Microsoft and Adobe products to its Known Exploited Vulnerabilities catalog in a single batch update.

What happened

The additions included Fortinet FortiClient EMS and FortiSandbox flaws that allow improper access control and unauthenticated OS command injection respectively, alongside vulnerabilities in Microsoft and Adobe software. CISA’s catalog entries require affected federal agencies to remediate on a defined schedule.

Why it matters

Batch KEV updates spanning multiple, unrelated vendors in the same week illustrate how broadly distributed exploitation activity has become across common enterprise software rather than concentrated in a single product line.

Security and infrastructure impact

Security teams should treat multi-vendor KEV batches as a prompt to review patch status across their full software inventory, not just the specific products named, since KEV additions often reflect exploitation trends that spread quickly to adjacent, similarly configured systems.

Sources

← Back to Technology News

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *