All incidents

CISA adds multiple exploited vulnerabilities to KEV catalog

vulnerabilityopenAug 25, 2026 — Aug 28, 2026
CISA adds multiple exploited vulnerabilities to KEV catalog

THE U.S. Cybersecurity and Infrastructure Security Agency has added six flaws to its Known Exploited Vulnerabilities catalogue, requiring immediate action from federal departments and critical infrastructure operators. The additions cover components in Red Hat products, the Linux kernel, Ajax.NET Professional, Microsoft SQL Server and Citrix NetScaler. Details were published in a CISA alert and reported by SecurityAffairs SecurityAffairs.

The newly listed vulnerabilities include CVE-2015-3246, a CVSS 5.1 race condition in Red Hat Libuser that can lead to privilege escalation, and CVE-2015-5287, a CVSS 7.8 flaw in Red Hat’s Automatic Bug Reporting Tool that also allows privilege escalation. CVE-2019-1068 carries a CVSS 8.8 score and enables remote code execution in Microsoft SQL Server, while CVE-2021-23758, rated CVSS 8.1, is a deserialization issue in Ajax.NET Professional that permits remote code execution.

CVE-2022-0995, scored CVSS 7.8, is an out-of-bounds write in the Linux kernel, and CVE-2026-8452, rated CVSS 8.8, is a memory buffer limitation in Citrix NetScaler that is currently being exploited.

CISA noted that CVE-2026-8452 is actively being used in attacks, whereas the other flaws have been observed in prior intrusion attempts. No specific threat actors have been attributed to these exploits at this time. The vulnerabilities affect widely deployed services, increasing the potential impact if left unpatched.

The agency has set patch deadlines of August 29 for some of the issues and September 9 for the remainder, urging administrators to prioritise remediation. This move highlights the growing trend of adversaries targeting legacy components alongside newer platforms, reinforcing the need for continuous vigilance across heterogeneous environments.

Organisations should begin by verifying which of the affected products are present in their inventories and then apply the latest vendor patches as soon as possible. Where immediate patching is not feasible, temporary mitigations such as disabling unused features, restricting network access to the vulnerable services, and employing web application firewalls or intrusion prevention signatures can reduce risk. Monitoring authentication logs, system calls and outbound connections for anomalous behaviour is also recommended.

Maintaining an accurate asset register, subscribing to CISA alerts and testing patches in a staging environment before production rollout will help ensure that remediation does not introduce instability. Teams should also consider vulnerability management platforms that automatically flag KEV entries and track remediation progress until all identified flaws are resolved.

Intelligence briefing updated Aug 28, 2026

CVE-2019-1068 8.8 KEV CVE-2026-8452 8.8 KEV CVE-2021-23758 8.1 KEV CVE-2015-5287 7.8 KEV CVE-2022-0995 7.8 KEV CVE-2015-3246 5.1 KEV
Root sourcewww.cisa.gov
Timeline Coverage

Swipe to explore timeline