Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

$13.74 million hack shuts down authorized Grinex exchange after tip-off

Mirai Variant Nexcorium exploits CVE-2024-3721 to hijack TBK DVR and attack DDoS botnet

Stripe and Airwallex came close enough to an acquisition, but now they’re chasing each other

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Added 6 known flaws exploited in CISA, Fortinet, Microsoft, and Adobe software.
Identity

Added 6 known flaws exploited in CISA, Fortinet, Microsoft, and Adobe software.

By April 14, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 14, 2026Vulnerability/Network Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added six security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

Here is the list of vulnerabilities:

CVE-2026-21643 (CVSS Score: 9.1) – A SQL injection vulnerability in Fortinet FortiClient EMS could allow an unauthenticated attacker to execute malicious code or commands via a specially crafted HTTP request. CVE-2020-9715 (CVSS score: 7.8) – A use-after-free vulnerability in Adobe Acrobat Reader could lead to remote code execution. CVE-2023-36424 (CVSS Score: 7.8) – An out-of-bounds read vulnerability in the Microsoft Windows Common Log File System driver could lead to privilege escalation. CVE-2023-21529 (CVSS score: 8.8) – Untrusted data deserialization in Microsoft Exchange Server could allow an authenticated attacker to execute remote code. CVE-2025-60710 (CVSS score: 7.8) – Improper link resolution before file access in the Windows task host process could allow an authorized attacker to locally escalate privileges. CVE-2012-1854 (CVSS score: 7.8) – Insecure library loading vulnerability in Microsoft Visual Basic for Applications (VBA) could allow remote code execution.

CVE-2026-21643 was added to the KEV catalog after Defused Cyber ​​announced that it detected an exploitation attempt targeting this flaw starting on March 24, 2026. Last week, Microsoft revealed that an attacker it tracks as Storm-1175 was weaponizing CVE-2023-21529 in attacks delivering Medusa ransomware.

Regarding CVE-2012-1854, the Windows maker acknowledged in an advisory released in July 2012 that it was aware of “limited targeted attacks” attempting to exploit this vulnerability. The exact nature of the attack is unknown at this time.

There are currently no public reports mentioning exploitation of the remaining three vulnerabilities. In view of active attacks, Federal Civilian Executive Branch (FCEB) agencies have until April 27, 2026 to apply the fixes.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleAmazon warehouse worker dies while working at Oregon facility
Next Article ShowDoc RCE flaw CVE-2025-0520 Actively exploited on unpatched servers

Related Posts

$13.74 million hack shuts down authorized Grinex exchange after tip-off

April 18, 2026

Mirai Variant Nexcorium exploits CVE-2024-3721 to hijack TBK DVR and attack DDoS botnet

April 18, 2026

Three Microsoft Defender zero-days were actively exploited. 2 are not yet patched

April 17, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

$13.74 million hack shuts down authorized Grinex exchange after tip-off

Mirai Variant Nexcorium exploits CVE-2024-3721 to hijack TBK DVR and attack DDoS botnet

Stripe and Airwallex came close enough to an acquisition, but now they’re chasing each other

Sam Altman’s Project World aims to expand his human verification empire. First stop is Tinder.

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.