Attackers Exploit Both Decade-Old and New Flaws in Federal Systems
Federal networks face active exploitation from vulnerabilities spanning from 2012 to 2026, showing attackers target both legacy and recent software flaws. This breaks the assumption that only recent vulnerabilities pose immediate risk, highlighting the need for continuous vigilance across all software versions.
CISA added seven vulnerabilities to its Known Exploited Vulnerabilities Catalog, including flaws in Microsoft Visual Basic for Applications (CVE-2012-1854), Adobe Acrobat and Reader, Microsoft Exchange Server, Microsoft Windows, and Fortinet products. These vulnerabilities have confirmed active exploitation and require prioritized remediation under federal directives.
The inclusion of a 2012 vulnerability alongside zero-days from 2026 signals that attackers maintain capabilities to exploit old and new weaknesses alike. This persistent threat landscape means organizations cannot rely solely on patching recent vulnerabilities but must also address legacy exposures to reduce risk.
CISA Adds Seven Known Exploited Vulnerabilities to Catalog | CISA
CISA Adds Seven Known Exploited Vulnerabilities to Catalog CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CISA Adds One Known Exploited Vulnerability to Catalog | CISA
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.