Attackers Exploit Both Decade-Old and New Flaws in Federal Systems
Federal networks face active exploitation from vulnerabilities spanning from 2012 to 2026, showing attackers target both legacy and recent software flaws. This breaks the assumption that only recent vulnerabilities pose immediate risk, highlighting the need for continuous vigilance across all software versions.
CISA added seven vulnerabilities to its Known Exploited Vulnerabilities Catalog, including flaws in Microsoft Visual Basic for Applications (CVE-2012-1854), Adobe Acrobat and Reader, Microsoft Exchange Server, Microsoft Windows, and Fortinet products. These vulnerabilities have confirmed active exploitation and require prioritized remediation under federal directives.
The inclusion of a 2012 vulnerability alongside zero-days from 2026 signals that attackers maintain capabilities to exploit old and new weaknesses alike. This persistent threat landscape means organizations cannot rely solely on patching recent vulnerabilities but must also address legacy exposures to reduce risk.