CISA adds six exploited vulnerabilities to the KEV catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after identifying evidence of active exploitation. The additions span Citrix NetScaler ADC and NetScaler Gateway, Microsoft SQL Server, the Linux kernel, Red Hat components and Ajax.NET Professional (AjaxPro).
For Federal Civilian Executive Branch agencies, CISA set an August 29, 2026 deadline to address CVE-2019-1068 in Microsoft SQL Server and CVE-2026-8452 in Citrix NetScaler products. The remaining four issues must be fixed by September 9, 2026.
NetScaler exploitation shows web-shell activity
CVE-2026-8452 is an improper restriction of operations within the bounds of a memory buffer in NetScaler ADC and NetScaler Gateway. CISA rates it as high severity, and the flaw can lead to denial of service.
Defused Cyber and Previdian, formerly KEVIntel, have warned that attackers are actively targeting the NetScaler issue. Previdian observed attackers deploying web shells named x.php and z.php, then running discovery commands including id and echo. Its telemetry recorded 36 exploitation attempts during 12 days from 12 unique attacker IP addresses across Switzerland, Germany, Hong Kong, Japan, the Netherlands, Russia, Singapore, Türkiye, the United States and Vietnam.
Six flaws affect server and application estates
CVE-2019-1068 is a remote code execution vulnerability in Microsoft SQL Server. An attacker could execute code in the context of the SQL Server Database Engine service account, although no public information currently explains how it is being exploited in the wild.
The Linux kernel flaw, CVE-2022-0995, is an out-of-bounds memory write that can allow a local user to obtain privileged access or cause denial of service. CISA also listed CVE-2015-5287 in Red Hat Automatic Bug Reporting Tool, where a symlink attack on a predictably named file can let qualifying local users gain privileges.
The remaining Red Hat issue, CVE-2015-3246 in libuser, is a race condition that may permit an authenticated local user to corrupt /etc/passwd, causing denial of service or privilege escalation. CVE-2021-23758 in AjaxPro is a deserialization-of-untrusted-data flaw that can enable remote code execution through arbitrary .NET classes.
Root causes remain a defensive priority
CISA added four of the vulnerabilities after Cisco Talos described UAT-10147, a Chinese cybercrime group targeting Windows and Linux web servers worldwide in education, media, technology and gaming. The agency also released a review of insecure software root causes and practical steps intended to reduce exploitation.
Its analysis of 2024 and 2025 CVE records found injection weaknesses were the largest category, with 7,701 CVEs in 2024 and 21,019 in 2025. CISA said memory-safety and improper-input-validation weaknesses appear disproportionately in KEVs relative to the broader CVE population, while attackers continue to exploit persistent known vulnerabilities in exposed assets and use AI to automate activity.
Businesses should treat the KEV additions as an operational patching and detection priority: identify exposed NetScaler, SQL Server, Linux, Red Hat and AjaxPro assets, apply vendor fixes on the applicable schedule, and review logs for the reported web-shell names and discovery commands.

