VYPR
kevPublished Aug 26, 2026· 1 source

CISA Adds Six Exploited Vulnerabilities to KEV Catalog, Reinforces Risk-Based Patching

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation and reinforcing the need for prioritized remediation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. This action is based on concrete evidence indicating that these vulnerabilities are actively being exploited by malicious cyber actors in the wild. The inclusion in the KEV Catalog serves as a critical alert to organizations, particularly federal agencies, about immediate threats that require prioritized attention.

The newly cataloged vulnerabilities span a range of software and operating systems, highlighting the diverse attack vectors currently in use. Among the additions are CVE-2015-3246, a race condition vulnerability in Red Hat Libuser; CVE-2015-5287, a privilege escalation vulnerability in the Red Hat Automatic Bug Reporting Tool; and CVE-2019-1068, a remote code execution vulnerability affecting Microsoft SQL Server. Additionally, CVE-2021-23758, a deserialization of untrusted data vulnerability in Ajax.NET Professional, CVE-2022-0995, an out-of-bounds write vulnerability in the Linux Kernel, and CVE-2026-8452, an improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway, have also been added.

These vulnerabilities represent frequent and significant attack vectors that pose substantial risks to the federal enterprise and, by extension, to organizations worldwide. CISA's Binding Operational Directive (BOD) 26-04, titled "Prioritizing Security Updates Based on Risk," mandates vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. This directive underscores the critical importance of the KEV Catalog by requiring federal agencies to expedite the remediation of high-risk vulnerabilities, especially those listed in the KEV Catalog that affect publicly exposed assets and grant complete control post-exploitation.

BOD 26-04 also establishes baseline expectations for agencies regarding the detection of potential compromises before patches are applied. While the directive specifically targets FCEB agencies, CISA strongly encourages all organizations, regardless of sector, to adopt a similar risk-based approach to vulnerability management. Prioritizing the patching of vulnerabilities identified in the KEV Catalog is a key recommendation for enhancing overall cybersecurity posture.

The inclusion of these six CVEs in the KEV Catalog signifies that threat actors are actively leveraging them, making them prime targets for further attacks. Organizations that have not yet patched these vulnerabilities are at a heightened risk of compromise. CISA's continuous monitoring and updating of the KEV Catalog are essential for providing timely intelligence on the most pressing cyber threats.

CISA remains committed to identifying and cataloging vulnerabilities that meet the specified criteria for active exploitation. The agency also provides a mechanism for the public to submit potential KEV additions through its KEV Nomination Form. To be considered for inclusion, a vulnerability must possess a CVE ID, demonstrable evidence of exploitation, and clear guidance on mitigation or patching.

The addition of these vulnerabilities serves as a stark reminder of the dynamic and persistent nature of cyber threats. Proactive vulnerability management, coupled with a keen awareness of actively exploited flaws, is crucial for effective defense against sophisticated adversaries. Organizations are urged to review their systems for the presence of these vulnerabilities and implement necessary security updates without delay.

This update from CISA reinforces the ongoing need for vigilance and rapid response in the cybersecurity landscape. By focusing resources on the most critical and actively exploited threats, organizations can better protect their digital assets and infrastructure from damaging cyberattacks.

Synthesized by Vypr AI