VYPR
kevPublished Aug 27, 2026· 1 source

CISA Adds Six Exploited Vulnerabilities to KEV Catalog, Including Flaws in Microsoft, Linux, and Citrix

CISA has added six actively exploited vulnerabilities affecting Microsoft, Linux, Red Hat, and Citrix products to its Known Exploited Vulnerabilities (KEV) catalog, mandating urgent patching.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has significantly updated its Known Exploited Vulnerabilities (KEV) catalog, adding six distinct vulnerabilities that are confirmed to be under active exploitation in the wild. This addition mandates that federal agencies and critical infrastructure organizations prioritize patching these flaws by specific deadlines to mitigate immediate risks.

The latest additions span a range of vendors and product types, highlighting the diverse threat landscape. Among the most critical is CVE-2026-8452, a high-severity memory overflow vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. This flaw, with a CVSS score of 8.8, can lead to denial of service if the appliance is configured for specific gateway functions. Citrix has already released patches for multiple versions of its NetScaler products, including 14.1 and 13.1 releases.

Another high-severity vulnerability added is CVE-2019-1068, a remote code execution (RCE) flaw in Microsoft SQL Server. Despite a patch being available for seven years, its inclusion in the KEV catalog underscores that unpatched systems remain vulnerable and are actively targeted. Attackers can exploit this by submitting a specially crafted query, allowing them to execute code with the privileges of the SQL Server Database Engine service account.

CISA has set an urgent deadline of August 29 for agencies to patch these two critical vulnerabilities. The remaining four vulnerabilities, all several years old, must be addressed by September 9. These include a race condition vulnerability in Red Hat's Libuser (CVE-2015-3246), a privilege escalation flaw in Red Hat's automatic bug reporting tool (CVE-2015-5287), a deserialization of untrusted data vulnerability in Ajax.NET Professional (CVE-2021-23758), and an out-of-bounds write vulnerability in the Linux kernel (CVE-2022-0995).

The inclusion of these older vulnerabilities in the KEV catalog serves as a stark reminder that legacy systems and unpatched software continue to pose significant risks. Threat actors often scan for and exploit known vulnerabilities for which patches have been available for years, targeting organizations that have failed to update their systems. This practice highlights the persistent challenge of vulnerability management and the importance of continuous patching and security hygiene.

CISA's KEV catalog is a crucial resource for organizations seeking to prioritize their security efforts. By identifying vulnerabilities that are actively being exploited, CISA enables defenders to focus on the most immediate threats. The agency strongly encourages all organizations, not just federal agencies, to review the KEV catalog regularly and implement the necessary security measures to protect their networks and data.

The broad range of affected products—from network appliances and database servers to operating system components—emphasizes the need for a comprehensive security strategy that covers diverse technology stacks. Organizations must maintain robust asset inventories, conduct regular vulnerability assessments, and ensure timely application of security updates across all their systems to stay ahead of evolving threats.

Synthesized by Vypr AI