Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-27 ยท updated: 2026-08-27 ยท tags: [incident, kev, advisory, vulnerability-management] ยท confidence: high ยท affected_sectors: [technology, government] ยท au_impact: true

CISA Adds Six Known Exploited Vulnerabilities to the KEV Catalog

CISA added six vulnerabilities to its Known Exploited Vulnerabilities Catalog on 2026-08-26 based on evidence of active exploitation: Citrix NetScaler ADC / Gateway (CVE-2026-8452), Microsoft SQL Server (CVE-2019-1068), Linux kernel (CVE-2022-0995), Ajax.NET Professional (CVE-2021-23758), Red Hat Libuser (CVE-2015-3246) and Red Hat ABRT (CVE-2015-5287).

CVE Product Type
CVE-2026-8452 Citrix NetScaler ADC/Gateway Memory bounds / network-edge
CVE-2019-1068 Microsoft SQL Server Remote code execution
CVE-2022-0995 Linux kernel Out-of-bounds write / privilege escalation
CVE-2021-23758 Ajax.NET Professional Deserialisation
CVE-2015-3246 Red Hat Libuser Race condition
CVE-2015-5287 Red Hat ABRT Privilege escalation

US federal agencies remediate under BOD 26-04 timelines. The Citrix NetScaler and SQL Server flaws merit review across organisations beyond the US federal enterprise, including in Australia and New Zealand.

Source