The Cybersecurity and Infrastructure Security Agency (CISA) added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on August 26, 2026, based on confirmed evidence of active exploitation. The catalog is the authoritative federal list of vulnerabilities that malicious actors are actively using in real-world attacks.
The newly added entries are:
- CVE-2026-8452 — Citrix NetScaler ADC and NetScaler Gateway improper restriction of operations within the bounds of a memory buffer vulnerability
- CVE-2022-0995 — Linux Kernel out-of-bounds write vulnerability
- CVE-2021-23758 — Ajax.NET Professional deserialization of untrusted data vulnerability
- CVE-2019-1068 — Microsoft SQL Server remote code execution vulnerability
- CVE-2015-5287 — Red Hat Automatic Bug Reporting Tool (ABRT) privilege escalation vulnerability
- CVE-2015-3246 — Red Hat Libuser race condition vulnerability
The mix illustrates a pattern CISA has flagged repeatedly this year: threat actors continue to exploit vulnerabilities dating back a decade alongside newly disclosed flaws, particularly where organizations have failed to retire legacy systems or apply available patches. The Citrix NetScaler entry is the most recent disclosure in the group and affects widely deployed application delivery and remote access infrastructure, making it an attractive target for initial network access.
Federal Remediation Requirements
Binding Operational Directive (BOD) 26-04, Prioritizing Security Updates Based on Risk, requires Federal Civilian Executive Branch (FCEB) agencies to remediate catalog vulnerabilities by CISA-assigned due dates, with particular urgency for flaws that grant an attacker total control of an affected asset post-exploitation. The directive also establishes baseline expectations for agencies to check whether a system was already compromised before a patch was applied.
While BOD 26-04 formally applies only to FCEB agencies, CISA continues to encourage all organizations — including operators of industrial, commercial, and critical infrastructure systems — to treat KEV Catalog membership as a high-priority signal for patch management, given that every entry reflects confirmed, not merely theoretical, exploitation activity.

Leave a Reply