THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, urging urgent action from government agencies and critical infrastructure organizations. Two notable vulnerabilities include CVE-2026-8452, a high-severity memory overflow in Citrix's NetScaler products, and CVE-2019-1068, a remote code execution flaw in Microsoft SQL Server. Both vulnerabilities have a CVSS rating of 8.8.
CISA has highlighted the need for immediate patching before deadlines of August 29 and September 9 for the remaining vulnerabilities, which also include flaws in Red Hat and Linux.