CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

August 27, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The flaws affect a range of products, including Citrix NetScaler ADC and Gateway, Microsoft SQL Server, the Linux Kernel, Red Hat ABRT and libuser, and Ajax.NET Professional.

The most notable addition is CVE-2026-8452, a high-severity memory buffer vulnerability in Citrix NetScaler ADC and Gateway that can lead to denial-of-service. Security firms Defused Cyber and Previdian (formerly KEVIntel) have observed active exploitation attempts, with attackers dropping web shells named ‘x.php’ and ‘z.php’ and running discovery commands. Telemetry shows 36 exploitation attempts from 12 unique IP addresses across multiple countries, including Switzerland, Germany, Hong Kong, Japan, the Netherlands, Russia, Singapore, Turkey, the U.S., and Vietnam.

Other vulnerabilities added include CVE-2019-1068 (Microsoft SQL Server remote code execution), CVE-2022-0995 (Linux Kernel out-of-bounds write), CVE-2015-5287 (Red Hat ABRT privilege escalation), CVE-2015-3246 (Red Hat libuser race condition), and CVE-2021-23758 (Ajax.NET Professional deserialization RCE). The inclusion of several of these flaws follows a report from Cisco Talos detailing a Chinese cybercrime group known as UAT-10147 that targets Windows and Linux web servers globally.

CISA is urging Federal Civilian Executive Branch (FCEB) agencies to apply fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, and for the remaining vulnerabilities by September 9, 2026. The agency also released a new vulnerability review highlighting that injection weaknesses are the most dominant vulnerability category, and that threat actors are increasingly using AI to automate exploitation of known flaws.

CVEs: CVE-2019-1068, CVE-2026-8452, CVE-2022-0995, CVE-2015-5287, CVE-2015-3246, CVE-2021-23758, CVE-2026-58231

Attack groups: UAT-10147

Companies: CISA, Citrix, Microsoft, Red Hat, Cisco Talos, Defused Cyber, Previdian

Products: Citrix NetScaler ADC, Citrix NetScaler Gateway, Microsoft SQL Server, Linux Kernel, Red Hat ABRT, Red Hat libuser, Ajax.NET Professional