Back to Feed
VulnerabilitiesAug 27, 2026

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

CISA adds six exploited vulnerabilities to KEV catalog, including NetScaler, Linux, and SQL Server bugs.

Summary

CISA has added six exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch them by specific deadlines. The newly added flaws include critical issues in Citrix NetScaler ADC and Gateway, Microsoft SQL Server, and the Linux Kernel. Exploitation efforts have been observed for the NetScaler vulnerability, with attackers dropping web shells and running discovery commands.

Full text

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs Ravie LakshmananAug 27, 2026Vulnerability / Web Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code execution vulnerability in Microsoft SQL Server that could allow an attacker to execute code in the context of the SQL Server Database Engine service account. CVE-2026-8452 - An improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway that could lead to denial-of-service. CVE-2022-0995 - An out-of-bounds memory write vulnerability in Linux Kernel that could allow a local user to gain privileged access or cause a denial of service on the system. CVE-2015-5287 - A privilege escalation vulnerability in Red Hat Automatic Bug Reporting Tool (ABRT) that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. CVE-2015-3246 - A race condition vulnerability in Red Hat libuser that could allow an authenticated local user to corrupt the /etc/passwd file to cause a denial of service or privilege escalation. CVE-2021-23758 - A deserialization of untrusted data vulnerability in Ajax.NET Professional (AjaxPro) that could allow for remote code execution via arbitrary .NET classes. The development comes as both Defused Cyber and Previdian (formerly KEVIntel) warned of active exploitation efforts aimed at CVE-2026-8452. "The attackers were dropping a web shell named 'x.php' and 'z.php,' and running discovery commands, like 'id' and 'echo,'" Previdian said in a LinkedIn post. Telemetry data shows that 36 exploitation attempts have been detected over the past 12 days from 12 unique attacker IP addresses from Switzerland, Germany, Hong Kong, Japan, the Netherlands, Russia, Singapore, Türkiye, the U.S., and Vietnam. The addition of CVE-2022-0995, CVE-2015-5287, CVE-2015-3246, and CVE-2021-23758 to the KEV catalog follows a report from Cisco Talos, which detailed a Chinese cybercrime group known as UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. There is currently no public information on how CVE-2019-1068 is being exploited in the wild. CISA is urging Federal Civilian Executive Branch (FCEB) agencies to apply fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, and for the rest by September 9, 2026. The additions also coincide with CISA's release of a new vulnerability review that delves into the root causes of insecure software and the practical steps organizations can take to remedy them and prevent exploitation. According to the agency's analysis of CVE records from 2024 and 2025, injection weaknesses emerged as the most dominant category, accounting for 7,701 CVEs in 2024 and 21,019 CVEs in 2025. CISA also stressed that threat actors are exploiting simple, known software vulnerabilities that remain persistent in exposed assets and that artificial intelligence (AI) is being used to automate exploitation efforts. "In FY2024 and FY2025, memory safety and improper input validation weaknesses appear disproportionately in KEVs compared to the full CVE population," CISA said. "For software providers, this finding underscores the importance of addressing the underlying weaknesses that often translate directly into real‑world exploitation. By reducing these root causes during software development, providers can help prevent vulnerabilities that are more likely to be targeted by threat actors." Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  linux, Microsoft, Vulnerability, Web Security ⚡ Top Stories This Week Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever — Read the New Report Build AI Agents and Automations Without Losing Security Control

Indicators of Compromise

  • cve — CVE-2019-1068
  • cve — CVE-2026-8452
  • cve — CVE-2022-0995
  • cve — CVE-2015-5287
  • cve — CVE-2015-3246
  • cve — CVE-2021-23758

Entities

NetScaler ADC (product)NetScaler Gateway (product)Microsoft SQL Server (product)Linux Kernel (product)Red Hat Automatic Bug Reporting Tool (ABRT) (product)Ajax.NET Professional (AjaxPro) (product)