April 6, 2026 — CISA added six actively exploited vulnerabilities spanning Fortinet, Microsoft and Adobe products to its Known Exploited Vulnerabilities catalog in a single batch update.
What happened
The additions included Fortinet FortiClient EMS and FortiSandbox flaws that allow improper access control and unauthenticated OS command injection respectively, alongside vulnerabilities in Microsoft and Adobe software. CISA’s catalog entries require affected federal agencies to remediate on a defined schedule.
Why it matters
Batch KEV updates spanning multiple, unrelated vendors in the same week illustrate how broadly distributed exploitation activity has become across common enterprise software rather than concentrated in a single product line.
Security and infrastructure impact
Security teams should treat multi-vendor KEV batches as a prompt to review patch status across their full software inventory, not just the specific products named, since KEV additions often reflect exploitation trends that spread quickly to adjacent, similarly configured systems.

Leave a Reply