CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation.

The vulnerabilities are listed below -

  • CVE-2019-1068 - A remote code execution vulnerability in  Microsoft SQL Server that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
  • CVE-2026-8452 - An improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway that could lead to denial-of-service.
  • CVE-2022-0995 - An out-of-bounds memory write vulnerability in  Linux Kernel that could allow a local user to gain privileged access or cause a denial of service on the system.
  • CVE-2015-5287 - A privilege escalation vulnerability in  Red Hat Automatic Bug Reporting Tool (ABRT) that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name.
  • CVE-2015-3246 - A race condition vulnerability in  Red Hat libuser that could allow an authenticated local user to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
  • CVE-2021-23758 - A deserialization of untrusted data vulnerability in Ajax.NET Professional (AjaxPro) that could allow for remote code execution via arbitrary .NET classes.

The development comes as both Defused Cyber and Previdian (formerly KEVIntel) warned of active exploitation efforts aimed at CVE-2026-8452.  "The attackers were dropping a web shell named 'x.php' and 'z.php,' and running discovery commands, like 'id' and 'echo,'" Previdian said in a LinkedIn post.

Telemetry data shows that 36 exploitation attempts have been detected over the past 12 days from 12 unique attacker IP addresses from Switzerland, Germany, Hong Kong, Japan, the Netherlands, Russia, Singapore, Türkiye, the U.S., and Vietnam.

The addition of CVE-2022-0995, CVE-2015-5287, CVE-2015-3246, and CVE-2021-23758 to the KEV catalog follows a report from Cisco Talos, which detailed a Chinese cybercrime group known as UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.

There is currently no public information on how CVE-2019-1068 is being exploited in the wild. CISA is urging Federal Civilian Executive Branch (FCEB) agencies to apply fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, and for the rest by September 9, 2026.

The additions also coincide with CISA's release of a new vulnerability review that delves into the root causes of insecure software and the practical steps organizations can take to remedy them and prevent exploitation.

According to the agency's analysis of CVE records from 2024 and 2025, injection weaknesses emerged as the most dominant category, accounting for 7,701 CVEs in 2024 and 21,019 CVEs in 2025. CISA also stressed that threat actors are exploiting simple, known software vulnerabilities that remain persistent in exposed assets and that artificial intelligence (AI) is being used to automate exploitation efforts.

"In FY2024 and FY2025, memory safety and improper input validation weaknesses appear disproportionately in KEVs compared to the full CVE population," CISA said.

"For software providers, this finding underscores the importance of addressing the underlying weaknesses that often translate directly into real‑world exploitation. By reducing these root causes during software development, providers can help prevent vulnerabilities that are more likely to be targeted by threat actors."

source: TheHackerNews