Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
government-vulnerability-catalogactively-exploited-vulnerabilitywidely-deployed-product-advisoryransomware-group-operation

CISA Expands KEV Catalog With Actively Exploited Enterprise Software Flaws

Updated 2mo agoFirst seen Apr 14, 20267 sources

CISA added 14 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog across two updates, citing evidence of active exploitation against widely used enterprise products from Fortinet, Microsoft, Adobe, Cisco, JetBrains, PaperCut, Kentico, Quest, and Zimbra. The newly listed flaws include issues in FortiClient EMS, Adobe Acrobat Reader, Microsoft Windows Common Log File System Driver, Microsoft Exchange Server, Host Process for Windows Tasks, Microsoft Visual Basic for Applications, JetBrains TeamCity, PaperCut NG/MF, Kentico Xperience, Quest KACE SMA, Zimbra Collaboration Suite, and Cisco Catalyst SD-WAN Manager, including privilege escalation, credential exposure, sensitive information disclosure, and cross-site scripting weaknesses.

Reporting tied several of the vulnerabilities to real-world intrusion activity and ransomware operations. Microsoft said threat actor Storm-1175 used CVE-2023-21529 to deliver Medusa ransomware, while CVE-2023-27351 has been linked to Lace Tempest deployments of Cl0p and LockBit. Defused Cyber also reported exploitation attempts against CVE-2026-21643, and CISA said federal civilian agencies must remediate the newly added flaws on deadlines running from late April into May 2026 under Binding Operational Directive requirements, while private-sector defenders were urged to prioritize the KEV entries for patching and exposure reduction.

Share:
CISA Expands KEV Catalog With Actively Exploited Enterprise Software Flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Apr 29, 20262mo ago

CISA adds ScreenConnect and Windows flaws to the KEV catalog

On April 29, 2026, CISA added CVE-2024-1708 in ConnectWise ScreenConnect and CVE-2026-32202 in Microsoft Windows to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The update signaled ongoing risk from unpatched self-hosted ScreenConnect systems and required federal agencies to remediate under Binding Operational Directive 22-01 timelines.

CISA adds Two vulnerabilities to KEV catalog - TheCyberThrone
Apr 21, 20262mo ago

CISA adds eight more actively exploited flaws to the KEV catalog

On April 21, 2026, CISA expanded the KEV catalog with eight additional vulnerabilities affecting PaperCut, JetBrains TeamCity, Kentico Xperience, Quest KACE SMA, Zimbra Collaboration Suite, and Cisco Catalyst SD-WAN Manager. The agency set remediation deadlines spanning April to May 2026 for federal agencies and urged private organizations to prioritize patching.

Apr 14, 20262mo ago

CISA adds six exploited flaws to the KEV catalog

On April 14, 2026, CISA added six vulnerabilities affecting Fortinet, Adobe, and Microsoft products to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. Federal Civilian Executive Branch agencies were ordered to remediate the listed flaws by April 27, 2026.

Storm-1175 uses CVE-2023-21529 to deliver Medusa ransomware

Microsoft said threat actor Storm-1175 exploited CVE-2023-21529 in Microsoft Exchange Server to deliver Medusa ransomware. This attribution was cited when CISA later added the flaw to the KEV catalog.

Mar 24, 20263mo ago

Exploitation attempts against CVE-2026-21643 observed

Defused Cyber reported exploitation attempts targeting CVE-2026-21643 beginning on March 24, 2026. The activity affected Fortinet FortiClient EMS and contributed to later KEV catalog action.

Dec 1, 20257mo ago

Akamai links Windows exploit chain to APT28 attacks in Europe and Ukraine

Akamai said the exploit chain involving CVE-2026-21510 and CVE-2026-21513, with CVE-2026-32202 stemming from an incomplete patch, was used in APT28 attacks targeting Ukraine and E.U. countries. The activity was described as ongoing since December 2025, adding new attribution and technical context beyond CISA's KEV listing.

CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV
Jan 1, 20233y ago

Lace Tempest linked to exploitation of PaperCut flaw CVE-2023-27351

CVE-2023-27351 in PaperCut NG/MF was previously associated with Lace Tempest activity deploying Cl0p and LockBit ransomware. The reference cites this prior criminal use as context for CISA's later KEV addition.

Jan 1, 201214y ago

Microsoft acknowledges targeted attacks exploiting CVE-2012-1854

Microsoft previously said CVE-2012-1854 in Visual Basic for Applications had been used in limited targeted attacks. This establishes that the flaw was exploited in the wild long before its 2026 KEV inclusion.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

53 LINKEDOpen in app
Malware
3 linked
Affected products
10 linked
Zimbra Collaboration SuiteKace Systems Management ApplianceXperienceTeamcityCatalyst SD-WAN ManagerAcrobat ReaderVisual Basic For ApplicationsExchange ServerWindows Common Log File System DriverForticlient Ems
Organizations
15 linked
Microsoft CorporationConnectwiseAkamai TechnologiesQuest SoftwareCisco SystemsZimbraPaperCut SoftwareJetbrainsKentico SoftwareArctic WolfFortinetAdobeThe Cyber ExpressDefused CyberDefused Cyber
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

CISA Expands KEV Catalog With Actively Exploited Enterprise Software Flaws | Mallory