CISA has documented a sustained wave of active vulnerability exploitation spanning April 13 through May 20, 2026. According to official CISA alerts tracked across this period, the agency added vulnerabilities in multiple batches: seven on April 13, two on April 14, one on April 16, one on April 22, one on April 23, two on April 28, one on April 30, one on May 1, one on May 6, one on May 7, one on May 8, one on May 15, and seven more on May 20—totaling at least 28 documented entries across 14 official CISA announcements.
The Hacker News reported that six of the early vulnerabilities specifically targeted Fortinet and Microsoft Exchange software, alongside Adobe products. This mix suggests adversaries are exploiting both edge-network infrastructure (Fortinet) and core email systems (Exchange)—both high-value targets for lateral movement and persistence.
CISA imposed a mandatory patching deadline of April 27, 2026, for federal civilian executive branch (FCEB) agencies, according to reporting on the initial wave. The continued addition of vulnerabilities beyond that date indicates either that threat actors had already begun exploitation before the deadline, or that new exploits were discovered after initial disclosure.
What matters: Known Exploited Vulnerabilities (KEV) Catalog entries mean CISA has corroborated active, real-world attack activity—not theoretical risk. When a flaw lands on the KEV list, it signals that patching is no longer optional for critical infrastructure operators. The frequency and diversity of additions across this six-week window suggests either a coordinated reconnaissance campaign, opportunistic exploitation of delayed patches, or discovery lag in detection and disclosure.
The pattern warrants attention: if patch windows are consistently lagging behind active exploitation windows, defenders are always playing catch-up. Organizations running Fortinet, Microsoft, or Adobe products in production should cross-reference their asset inventories against the full KEV Catalog and confirm patch status—not assume patches were applied when announced.

