“36 exploitation attempts have been detected over the past 12 days,” according to telemetry tied to a recently added entry in the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalog — a precise count that signals active, distributed scanning and exploitation activity tied to a newly listed Citrix NetScaler flaw and five other long‑running vulnerabilities.
Six exploited flaws added to CISA’s KEV
CISA added six vulnerabilities to its KEV catalog, citing evidence of active exploitation for at least one high‑severity bug. The vulnerabilities listed by the agency are:
- CVE-2019-1068 — A remote code execution vulnerability in Microsoft SQL Server that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
- CVE-2026-8452 — An improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway that could lead to denial-of-service.
- CVE-2022-0995 — An out-of-bounds memory write vulnerability in Linux Kernel that could allow a local user to gain privileged access or cause a denial of service on the system.
- CVE-2015-5287 — A privilege escalation vulnerability in Red Hat Automatic Bug Reporting Tool (ABRT) that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name.
- CVE-2015-3246 — A race condition vulnerability in Red Hat libuser that could allow an authenticated local user to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
- CVE-2021-23758 — A deserialization of untrusted data vulnerability in Ajax.NET Professional (AjaxPro) that could allow for remote code execution via arbitrary .NET classes.
Active exploitation centered on CVE-2026-8452; web shells observed
Security firms Defused Cyber and Previdian (formerly KEVIntel) warned of active exploitation efforts aimed at CVE-2026-8452. Previdian reported in a LinkedIn post that “The attackers were dropping a web shell named 'x.php' and 'z.php,' and running discovery commands, like 'id' and 'echo.'” CISA’s placement of the Citrix NetScaler issue in KEV reflects that evidence of exploitation.
For CVE-2019-1068 (Microsoft SQL Server), the agency noted there is currently no public information on how it is being exploited in the wild.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadTelemetry snapshot: 36 attempts from 12 unique IPs across multiple countries
Previdian’s telemetry shows 36 exploitation attempts detected over the prior 12‑day window, originating from 12 unique attacker IP addresses. The addresses resolved to locations in Switzerland, Germany, Hong Kong, Japan, the Netherlands, Russia, Singapore, Türkiye, the U.S., and Vietnam.
CISA deadlines for Federal Civilian Executive Branch agencies
CISA is urging Federal Civilian Executive Branch (FCEB) agencies to apply fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026. The agency set a later remediation deadline of September 9, 2026 for the remaining four vulnerabilities added to KEV.
Cisco Talos links additions to UAT-10147 activity against web servers
The four KEV additions tied to Linux and server tooling — CVE-2022-0995, CVE-2015-5287, CVE-2015-3246, and CVE-2021-23758 — follow a Cisco Talos report that detailed activity by a Chinese cybercrime group known as UAT-10147. Talos said UAT-10147 is targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.
CISA’s vulnerability review: injection defects, memory safety, and AI‑assisted exploitation
Alongside the KEV additions, CISA published a vulnerability review that examines root causes of insecure software and practical steps to mitigate them. CISA’s analysis of CVE records from 2024 and 2025 found injection weaknesses to be the most dominant category — accounting for 7,701 CVEs in 2024 and 21,019 CVEs in 2025.
The agency also warned that “threat actors are exploiting simple, known software vulnerabilities that remain persistent in exposed assets and that artificial intelligence (AI) is being used to automate exploitation efforts.” CISA summarized a pattern in KEVs: “In FY2024 and FY2025, memory safety and improper input validation weaknesses appear disproportionately in KEVs compared to the full CVE population.” The agency concluded: “For software providers, this finding underscores the importance of addressing the underlying weaknesses that often translate directly into real‑world exploitation. By reducing these root causes during software development, providers can help prevent vulnerabilities that are more likely to be targeted by threat actors.”
The record is specific and immediate: CISA has flagged six known flaws, telemetry shows dozens of attempts from diverse IPs, and two remediation deadlines for FCEB agencies fall within days. Whether those timelines and the newly public analysis of root causes will reduce exposure to the NetScaler exploits, to the Linux kernel and server tooling weaknesses, and to automated AI‑driven exploitation is the near‑term test implied by the agency’s actions and by the observed activity.




