type: incident ยท created: 2026-08-27 ยท updated: 2026-08-27 ยท tags: [incident, kev, advisory, vulnerability-management] ยท confidence: high ยท affected_sectors: [technology, government] ยท au_impact: true
CISA Adds Six Known Exploited Vulnerabilities to the KEV Catalog
CISA added six vulnerabilities to its Known Exploited Vulnerabilities Catalog on 2026-08-26 based on evidence of active exploitation: Citrix NetScaler ADC / Gateway (CVE-2026-8452), Microsoft SQL Server (CVE-2019-1068), Linux kernel (CVE-2022-0995), Ajax.NET Professional (CVE-2021-23758), Red Hat Libuser (CVE-2015-3246) and Red Hat ABRT (CVE-2015-5287).
| CVE | Product | Type |
|---|---|---|
| CVE-2026-8452 | Citrix NetScaler ADC/Gateway | Memory bounds / network-edge |
| CVE-2019-1068 | Microsoft SQL Server | Remote code execution |
| CVE-2022-0995 | Linux kernel | Out-of-bounds write / privilege escalation |
| CVE-2021-23758 | Ajax.NET Professional | Deserialisation |
| CVE-2015-3246 | Red Hat Libuser | Race condition |
| CVE-2015-5287 | Red Hat ABRT | Privilege escalation |
US federal agencies remediate under BOD 26-04 timelines. The Citrix NetScaler and SQL Server flaws merit review across organisations beyond the US federal enterprise, including in Australia and New Zealand.