Skip to main content
Emerging Threats

CISA Flags Six Exploited Flaws in Microsoft, Linux, Citrix Products

Empty computer workstation on a neutral-colored desk in a generic office setting with a laptop and peripherals.

“CISA added six new flaws to its Known Exploited Vulnerabilities (KEV) catalog in a single day on August 26,” the agency reported — a succinct signal that threat actors remain active against both old and recently disclosed software weaknesses.

CISA’s August 26 KEV action and what the listing means

On August 26 the U.S. Cybersecurity and Infrastructure Security Agency (CISA) placed six vulnerabilities on its Known Exploited Vulnerabilities (KEV) catalog. By definition for the KEV list, each addition reflects the agency’s determination that there is evidence of exploitation “in the wild.” CISA set specific remediation deadlines: two vulnerabilities required patches by August 29, and the remaining four — all several years old — were given a September 9 patching deadline.

CVE-2026-8452: memory overflow in Citrix NetScaler ADC and NetScaler Gateway

One of the two highest-severity entries added on August 26 is CVE-2026-8452, a memory overflow vulnerability affecting NetScaler ADC and NetScaler Gateway. Citrix reported the flaw at the end of June and assigned it a CVSS severity rating of 8.8. According to the vendor and the KEV listing, exploitation can cause unpredictable or erroneous behavior and denial of service (DoS) when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server.

Citrix has published fixes. The vendor lists the following patched releases:

  • NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP

CVE-2019-1068: Microsoft SQL Server RCE still exploited despite seven-year-old patch

The other high-severity entry is CVE-2019-1068, a remote code execution vulnerability in Microsoft SQL Server that also carries a CVSS rating of 8.8. The KEV addition underscores that, even though a patch has been available for seven years, threat actors continue to target unpatched instances. Exploitation involves submitting a specially crafted query to an affected SQL Server; a successful exploit can allow an attacker to execute code in the context of the SQL Server Database Engine service account.

CISA directed government agencies to apply the patches for both CVE-2026-8452 (Citrix NetScaler) and CVE-2019-1068 (Microsoft SQL Server) by August 29.

Four legacy vulnerabilities added and their deadlines

Alongside the two high-severity flaws, CISA added four older vulnerabilities on August 26 and set a common remediation date of September 9. The KEV entries and their CVSS ratings are:

  • CVE-2015-3246 — Red Hat Libuser race condition vulnerability (CVSS 5.1)
  • CVE-2015-5287 — Red Hat automatic bug reporting tool privilege escalation vulnerability (CVSS 7.8)
  • CVE-2021-23758 — Ajax.NET Professional deserialization of untrusted data vulnerability (CVSS 8.1)
  • CVE-2022-0995 — Linux kernel out-of-bounds write vulnerability (CVSS 7.8)

What this means for government agencies, critical infrastructure organizations, and system administrators

Government agencies were given explicit, short deadlines by CISA: apply patches for the Citrix and Microsoft SQL Server flaws by August 29, and address the four older vulnerabilities by September 9. The KEV designation signals those agencies that exploitation is known to be occurring and that rapid remediation is mandated.

Critical infrastructure organizations face the same timelines; the KEV listing is intended to prompt swift action from organizations whose services are essential and who often run the affected products in production environments.

System administrators and operators must reconcile two realities spelled out by the listing: several of the added vulnerabilities are legacy flaws with patches available for years, highlighted by CVE-2019-1068 where a seven-year-old patch has not stopped active exploitation; and at least one vulnerability — CVE-2026-8452 — is newly reported by a vendor (Citrix) with patch releases already published for specific NetScaler ADC and Gateway versions.

CISA’s August 26 update is a compact, specific directive: evidence of active exploitation exists, fixes are available for the affected products, and timelines have been set for remediation. For agencies and organizations that still operate the listed software, the record is plain — the agency expects patches applied within days for two high-risk flaws and within two weeks for the remaining four.

Original story