# CISA Adds Six Bugs to KEV Catalog

Published: 2026-08-26 · Severity: severe · Sectors: government-national
Canonical: https://vorant.io/reports/fa4ccb13-f4a4-52a0-a2d1-39a8335a2e08/cisa-adds-six-bugs-to-kev-catalog

> CISA added six actively exploited vulnerabilities—including flaws in Citrix NetScaler, SQL Server, and Linux kernel—to its Known Exploited Vulnerabilities catalog.

CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog with six new CVEs based on confirmed evidence of active exploitation. The list spans a range of products and ages, including older Red Hat Libuser and ABRT flaws, a 2019 Microsoft SQL Server RCE, a 2021 Ajax.NET Professional deserialization bug, a 2022 Linux kernel out-of-bounds write issue, and a newly disclosed Citrix NetScaler ADC/Gateway memory-corruption vulnerability (CVE-2026-8452). The inclusion of older CVEs alongside a fresh Citrix flaw underscores that legacy unpatched systems remain viable attack vectors for adversaries.

Under Binding Operational Directive (BOD) 26-04, FCEB agencies must prioritize remediation of KEV-listed vulnerabilities on internet-facing assets that could grant full post-exploitation control, and must verify whether systems were compromised prior to patching. While BOD 26-04 is mandatory only for federal civilian agencies, CISA recommends all organizations adopt similar risk-based patching priorities, particularly for the Citrix NetScaler vulnerability given the product's history as a high-value target for both criminal and state-sponsored actors.

Defenders should inventory affected products (Red Hat systems with Libuser/ABRT, Microsoft SQL Server, Ajax.NET Professional deployments, vulnerable Linux kernel versions, and Citrix NetScaler ADC/Gateway) and apply vendor patches immediately, with priority given to internet-exposed Citrix NetScaler instances given the severity and active exploitation of CVE-2026-8452.

## Mentioned in this report

- Vulnerabilities: CVE-2015-3246 (KEV), CVE-2015-5287 (KEV), CVE-2019-1068 (KEV), CVE-2021-23758 (KEV), CVE-2022-0995 (KEV), CVE-2026-8452 (KEV)

Source reporting: https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/fa4ccb13-f4a4-52a0-a2d1-39a8335a2e08/cisa-adds-six-bugs-to-kev-catalog.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
