VORANT. Threat Intelligence Sign in Get the full feed

CISA Adds Six Bugs to KEV Catalog

severe vulnerability government-national

CISA added six actively exploited vulnerabilities—including flaws in Citrix NetScaler, SQL Server, and Linux kernel—to its Known Exploited Vulnerabilities catalog.

CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog with six new CVEs based on confirmed evidence of active exploitation. The list spans a range of products and ages, including older Red Hat Libuser and ABRT flaws, a 2019 Microsoft SQL Server RCE, a 2021 Ajax.NET Professional deserialization bug, a 2022 Linux kernel out-of-bounds write issue, and a newly disclosed Citrix NetScaler ADC/Gateway memory-corruption vulnerability (CVE-2026-8452). The inclusion of older CVEs alongside a fresh Citrix flaw underscores that legacy unpatched systems remain viable attack vectors for adversaries.

Under Binding Operational Directive (BOD) 26-04, FCEB agencies must prioritize remediation of KEV-listed vulnerabilities on internet-facing assets that could grant full post-exploitation control, and must verify whether systems were compromised prior to patching. While BOD 26-04 is mandatory only for federal civilian agencies, CISA recommends all organizations adopt similar risk-based patching priorities, particularly for the Citrix NetScaler vulnerability given the product's history as a high-value target for both criminal and state-sponsored actors.

Defenders should inventory affected products (Red Hat systems with Libuser/ABRT, Microsoft SQL Server, Ajax.NET Professional deployments, vulnerable Linux kernel versions, and Citrix NetScaler ADC/Gateway) and apply vendor patches immediately, with priority given to internet-exposed Citrix NetScaler instances given the severity and active exploitation of CVE-2026-8452.

Mentioned in this report

Vulnerabilities CVE-2015-3246KEVCVE-2015-5287KEVCVE-2019-1068KEVCVE-2021-23758KEVCVE-2022-0995KEVCVE-2026-8452KEV

Source reporting: https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free