THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several critical vulnerabilities to its Known Exploited Vulnerabilities catalog including flaws in Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler. Key vulnerabilities include:
1. **CVE-2015-3246**: Red Hat Libuser race condition which may lead to privilege escalation.
2. **CVE-2015-5287**: Privilege escalation in Red Hat's Automatic Bug Reporting Tool.
3. **CVE-2019-1068**: Remote code execution in Microsoft SQL Server.
4. **CVE-2021-23758**: Ajax.NET vulnerability allowing remote code execution.
5. **CVE-2022-0995**: Out-of-bounds write in Linux Kernel.
6. **CVE-2026-8452**: Citrix NetScaler buffer operation limitation vulnerability, actively exploited. Federal agencies are mandated to address these vulnerabilities by specified deadlines to enhance network security.