CISA Adds Six Exploited Flaws to KEV Catalog
CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog on August 26, including high-severity flaws in Citrix and Microsoft products.

The US Cybersecurity and Infrastructure Security Agency (CISA) added six security flaws to its Known Exploited Vulnerabilities (KEV) catalog on August 26. The agency is urging federal agencies and critical infrastructure organizations to apply patches promptly.
A KEV listing signifies that CISA has confirmed active exploitation of these vulnerabilities in the wild. The August 26 update included two high-severity issues alongside four older flaws.
Critical Vulnerability Exploited in Citrix Products
The first high-severity flaw is tracked as CVE-2026-8452. It is a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway. Citrix reported the bug in late June and assigned it a CVSS severity score of 8.8.
Exploitation can cause unpredictable behavior and denial-of-service (DoS). This occurs when the appliance is configured as a Gateway or AAA virtual server. Citrix has released patches in specific software updates.
| Product | Patched Version |
|---|---|
| NetScaler ADC and NetScaler Gateway | 14.1-72.61 and later |
| NetScaler ADC and NetScaler Gateway 13.1 | 13.1-63.18 and later releases |
| NetScaler ADC 14.1-FIPS | 14.1-72.61 FIPS and later releases |
| NetScaler ADC 13.1-FIPS and 13.1-NDcPP | 13.1.37.272 and later releases |
Vendor-Issued Patches for CVE
The second high-severity flaw is CVE-2019-1068. This is a remote code execution (RCE) vulnerability in Microsoft SQL Server. It also carries a CVSS score of 8.8.
A patch has been available for seven years. Its addition to the KEV catalog indicates threat actors are still targeting unpatched systems. Attackers can exploit it by submitting a specially crafted query. Successful exploitation allows code execution under the SQL Server Database Engine service account's context.
CISA mandated that federal agencies apply patches for these two critical vulnerabilities by August 29.
Additional Older Flaws Require Patching
CISA added four other, older vulnerabilities to the catalog on the same day. The agency set a patch deadline of September 9 for these issues.
The list includes several-year-old flaws in Red Hat, Ajax.NET, and the Linux kernel. Their CVSS scores range from moderate to high severity.
| CVE ID | Product / Component | Vulnerability Type | CVSS Score |
|---|---|---|---|
| CVE-2015-3246 | Red Hat Libuser | Race Condition | 5.1 |
| CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool | Privilege Escalation | 7.8 |
| CVE-2021-23758 | Ajax.NET Professional | Deserialization of Untrusted Data | 8.1 |
| CVE-2022-0995 | Linux Kernel | Out-of-Bounds Write | 7.8 |
CISA's advisory, reported by Infosecurity Magazine, underscores the ongoing risk posed by both new and old unpatched software.





