Zero Day Room
Live
Vulnerabilities

CISA Adds Six Exploited Flaws to KEV Catalog

CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog on August 26, including high-severity flaws in Citrix and Microsoft products.

CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog on August 26, including high-severity flaws...

The US Cybersecurity and Infrastructure Security Agency (CISA) added six security flaws to its Known Exploited Vulnerabilities (KEV) catalog on August 26. The agency is urging federal agencies and critical infrastructure organizations to apply patches promptly.

A KEV listing signifies that CISA has confirmed active exploitation of these vulnerabilities in the wild. The August 26 update included two high-severity issues alongside four older flaws.

Critical Vulnerability Exploited in Citrix Products

The first high-severity flaw is tracked as CVE-2026-8452. It is a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway. Citrix reported the bug in late June and assigned it a CVSS severity score of 8.8.

Exploitation can cause unpredictable behavior and denial-of-service (DoS). This occurs when the appliance is configured as a Gateway or AAA virtual server. Citrix has released patches in specific software updates.

ProductPatched Version
NetScaler ADC and NetScaler Gateway14.1-72.61 and later
NetScaler ADC and NetScaler Gateway 13.113.1-63.18 and later releases
NetScaler ADC 14.1-FIPS14.1-72.61 FIPS and later releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP13.1.37.272 and later releases

Vendor-Issued Patches for CVE

The second high-severity flaw is CVE-2019-1068. This is a remote code execution (RCE) vulnerability in Microsoft SQL Server. It also carries a CVSS score of 8.8.

A patch has been available for seven years. Its addition to the KEV catalog indicates threat actors are still targeting unpatched systems. Attackers can exploit it by submitting a specially crafted query. Successful exploitation allows code execution under the SQL Server Database Engine service account's context.

CISA mandated that federal agencies apply patches for these two critical vulnerabilities by August 29.

Additional Older Flaws Require Patching

CISA added four other, older vulnerabilities to the catalog on the same day. The agency set a patch deadline of September 9 for these issues.

The list includes several-year-old flaws in Red Hat, Ajax.NET, and the Linux kernel. Their CVSS scores range from moderate to high severity.

CVE IDProduct / ComponentVulnerability TypeCVSS Score
CVE-2015-3246Red Hat LibuserRace Condition5.1
CVE-2015-5287Red Hat Automatic Bug Reporting ToolPrivilege Escalation7.8
CVE-2021-23758Ajax.NET ProfessionalDeserialization of Untrusted Data8.1
CVE-2022-0995Linux KernelOut-of-Bounds Write7.8

CISA's advisory, reported by Infosecurity Magazine, underscores the ongoing risk posed by both new and old unpatched software.

Related coverage

More from Vulnerabilities